Trojan

What is “Trojan-PSW.Win32.Racealer.cxy”?

Malware Removal

The Trojan-PSW.Win32.Racealer.cxy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Racealer.cxy virus can do?

  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (5 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Attempts to create or modify system certificates
  • Collects information to fingerprint the system

Related domains:

doc-0s-44-docs.googleusercontent.com

How to determine Trojan-PSW.Win32.Racealer.cxy?


File Info:

crc32: 139D5811
md5: 7fbd9b70e6cee8f25b5839c64edf87c6
name: 123.exe
sha1: e7e0d4b572b30c1d7002016018b833ed67e90902
sha256: 0e2901166a12f0b954c9a703b0624ad49d75f04d7dad8508c81818d315e7de2a
sha512: 3d549431c48e09217a13186f3466a4c959f7ac407e26b2f2275fbf10aeb82bdedc1254cd2b1ff6ae6a4130d1a9bca25711d020e96590c351a4f3253f34fce85d
ssdeep: 12288:mM/bG+Ecw2ZdnrgDcSlnay8dBm5K86prmJvup3qrSartbE:mM/6+l1xMDcgY6Yg
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-PSW.Win32.Racealer.cxy also known as:

DrWebTrojan.PWS.Stealer.28036
MicroWorld-eScanGen:Variant.Razy.594574
FireEyeGeneric.mg.7fbd9b70e6cee8f2
Qihoo-360Win32/Trojan.PSW.840
ALYacGen:Variant.Razy.594574
CylanceUnsafe
SangforMalware
K7AntiVirusSpyware ( 0054b83d1 )
BitDefenderGen:Variant.Razy.594574
Cybereasonmalicious.572b30
TrendMicroTROJ_GEN.R002C0WB720
BitDefenderThetaGen:NN.ZexaF.34084.HqW@ayVZtfh
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
ClamAVWin.Malware.Ulise-7344017-0
GDataGen:Variant.Razy.594574
KasperskyTrojan-PSW.Win32.Racealer.cxy
AlibabaTrojanSpy:Win32/Generic.6e014a04
AegisLabTrojan.Win32.Racealer.i!c
RisingStealer.Raccoon!1.BD9D (CLOUD)
Ad-AwareGen:Variant.Razy.594574
SophosMal/Generic-S
F-SecureTrojan.TR/AD.StellarStealer.pskqb
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Adopshel.hh
Trapminesuspicious.low.ml.score
EmsisoftGen:Variant.Razy.594574 (B)
AviraTR/AD.StellarStealer.pskqb
MAXmalware (ai score=86)
Endgamemalicious (high confidence)
ArcabitTrojan.Razy.D9128E
ZoneAlarmTrojan-PSW.Win32.Racealer.cxy
MicrosoftTrojan:Win32/Occamy.C
Acronissuspicious
McAfeeArtemis!7FBD9B70E6CE
VBA32BScope.TrojanSpy.MSIL.Stealer
MalwarebytesSpyware.RaccoonStealer
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Spy.Agent.PQZ
TrendMicro-HouseCallTROJ_GEN.R002C0WB720
TencentWin32.Trojan-qqpass.Qqrob.Ammv
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_97%
FortinetW32/Agent.PQZ!tr.spy
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan-PSW.Win32.Racealer.cxy?

Trojan-PSW.Win32.Racealer.cxy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment