Trojan

Should I remove “Trojan:Win32/Racealer.RND!MTB”?

Malware Removal

The Trojan:Win32/Racealer.RND!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Racealer.RND!MTB virus can do?

  • Attempts to connect to a dead IP:Port (5 unique times)
  • Performs some HTTP requests
  • Steals private information from local Internet browsers
  • Attempts to access Bitcoin/ALTCoin wallets
  • Attempts to create or modify system certificates
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz
telete.in
apps.identrust.com
puffpuff421.top

How to determine Trojan:Win32/Racealer.RND!MTB?


File Info:

crc32: B1630502
md5: ae6f291866a56b15c2ab6e26ccc9bb03
name: AE6F291866A56B15C2AB6E26CCC9BB03.mlw
sha1: 014646c0b4b47ddcc25fbbe5a20bc2c63d595530
sha256: 53fb33119de8332150c17aefef898ea06246b8a9b0ff5cf4c286b45b3a955ddc
sha512: 7a5a693cc2a633da610ef04fc320fcedacec153d49658fb645ed579cd6881ccac0c3aa4a63bd3188e68572d9e806fcf3eae9b734904a7fa7824b66c8834b56cc
ssdeep: 12288:94JAmrX+c6ZByss77aYlrxSvzDh14dG+2o7fAguvcL+L6Fhkfw8ffh6:6JN6ZByb7aY1xeS/x4J6
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Racealer.RND!MTB also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen2.58526
MicroWorld-eScanGen:Variant.Razy.704872
FireEyeGeneric.mg.ae6f291866a56b15
ALYacGen:Variant.Razy.704872
CylanceUnsafe
SangforMalware
BitDefenderGen:Variant.Razy.704872
Cybereasonmalicious.0b4b47
BitDefenderThetaGen:NN.ZexaF.34590.JqW@aqzMWBf
SymantecML.Attribute.HighConfidence
APEXMalicious
ClamAVWin.Malware.Ulise-7344017-0
Ad-AwareGen:Variant.Razy.704872
F-SecureHeuristic.HEUR/AGEN.1137972
InvinceaGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.Generic.hh
EmsisoftTrojan-Spy.Agent (A)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.PSW.Racealer.yd
eGambitUnsafe.AI_Score_96%
AviraHEUR/AGEN.1137972
Antiy-AVLTrojan[PSW]/Win32.Racealer
MicrosoftTrojan:Win32/Racealer.RND!MTB
ArcabitTrojan.Razy.DAC168
GDataGen:Variant.Razy.704872
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Raccoon.R329741
McAfeeGenericRXJR-SB!AE6F291866A5
MAXmalware (ai score=87)
VBA32BScope.TrojanSpy.MSIL.Stealer
MalwarebytesSpyware.RaccoonStealer
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Spy.Agent.PQZ
RisingSpyware.Agent!8.C6 (TFE:5:7LgsembMfdD)
IkarusTrojan.Win32.Delf
FortinetW32/Agent.PQZ!tr
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Trojan:Win32/Racealer.RND!MTB?

Trojan:Win32/Racealer.RND!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment