Trojan

Should I remove “Trojan-PSW.Win32.Racealer.hcn”?

Malware Removal

The Trojan-PSW.Win32.Racealer.hcn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Racealer.hcn virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (5 unique times)
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
telete.in
apps.identrust.com

How to determine Trojan-PSW.Win32.Racealer.hcn?


File Info:

crc32: F7D02210
md5: ddb7ae232eb5ab80aa4907ac96468531
name: ca6cfa15ce28d55282f68482e44ea0d4c6c2dc0bab2b19f1d6fa56f732ae4c29.exe
sha1: 38c9b4d60c18d236f8f1af2b2ebd586973c64ba7
sha256: ca6cfa15ce28d55282f68482e44ea0d4c6c2dc0bab2b19f1d6fa56f732ae4c29
sha512: d52a8568cbcb019822f0865a9174a974a3aa479ef51d35e8b215fcc6cee0adf106d6145899cbe3638a7b2722d787ee05aa0f00ac1dc65a966fb4d672777ecc4e
ssdeep: 6144:Ih/wJNUrZLNi9v48RD5GwxHJCbsIb1tsaq7HE1FZa8aH4rqCy7wEX/wDvbY:awcrZLyD5G2HI5hVqDE1PaDYg
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalSurnames: edzgkphvesw.ixe
FileVersionz: 1.2.6.1
TranslationUz: 0x0252 0x0529

Trojan-PSW.Win32.Racealer.hcn also known as:

BkavHW32.Packed.
MicroWorld-eScanTrojan.GenericKD.43440353
FireEyeGeneric.mg.ddb7ae232eb5ab80
MalwarebytesTrojan.MalPack.GS
SangforMalware
BitDefenderTrojan.GenericKD.43440353
Cybereasonmalicious.60c18d
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34130.DyW@aGuAHTgG
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:PWSX-gen [Trj]
GDataTrojan.GenericKD.43440353
KasperskyTrojan-PSW.Win32.Racealer.hcn
TencentWin32.Trojan-qqpass.Qqrob.Wvkp
Ad-AwareTrojan.GenericKD.43440353
SophosMal/Generic-S
ComodoMalware@#l899qcu38voc
F-SecureTrojan.TR/AD.StellarStealer.tkcot
TrendMicroTrojan.Win32.WACATAC.THGOEBO
EmsisoftTrojan.GenericKD.43440353 (B)
SentinelOneDFI – Malicious PE
AviraTR/AD.StellarStealer.tkcot
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D296D8E1
ZoneAlarmTrojan-PSW.Win32.Racealer.hcn
MicrosoftTrojan:Win32/Wacatac.C!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.MalPe.R343012
McAfeePacked-GAO!DDB7AE232EB5
CylanceUnsafe
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HEQL
TrendMicro-HouseCallTrojan.Win32.WACATAC.THGOEBO
RisingMalware.Heuristic!ET#92% (RDMK:cmRtazoux0EnO4YvWkWMDScquNXe)
MAXmalware (ai score=88)
eGambitUnsafe.AI_Score_96%
FortinetW32/Packed.GAO!tr
WebrootW32.Trojan.Gen
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM10.1.6222.Malware.Gen

How to remove Trojan-PSW.Win32.Racealer.hcn?

Trojan-PSW.Win32.Racealer.hcn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment