Trojan

Trojan-PSW.Win32.Racealer.koa removal guide

Malware Removal

The Trojan-PSW.Win32.Racealer.koa is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Racealer.koa virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Steals private information from local Internet browsers
  • Creates a hidden or system file
  • Attempts to access Bitcoin/ALTCoin wallets
  • Attempts to create or modify system certificates
  • Collects information to fingerprint the system

Related domains:

telete.in
apps.identrust.com
midnightsituation.top

How to determine Trojan-PSW.Win32.Racealer.koa?


File Info:

crc32: DC2662E8
md5: 0f70ab202fe9257f08e088320879b89c
name: 0F70AB202FE9257F08E088320879B89C.mlw
sha1: e52a72956f453bc1f9722edd45b1b24a20c6f38d
sha256: d5f6c0a7fa3c0fbb136f75e322a416a75f81f255c527f6f3bbbc8a7a72b8d0e1
sha512: c719eecb0ae7912fb480a1523b3dc571bb07a0f74be2f233ad047cf55ea1fcc3774f342339afee104056567a764f2ddd22f83301fc7e7f51640c5e9b11c341a7
ssdeep: 12288:e4YsHwYtBV9jiJDBO8TPILVDDriig2hCfmUW8VCMdJE5fK:e4Y9YtBVkupgzfmUWNoJE5fK
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 ConEmu.Maximus5@gmail.com
Assembly Version: 2.4.7.0
InternalName: ConEmuSetup.201101.exe
FileVersion: 2.4.7.0
CompanyName: ConEmu-Maximus5
Comments: ConEmu Installer
ProductName: ConEmu
ProductVersion: 2.4.7.0
FileDescription: ConEmu Installer
OriginalFilename: ConEmuSetup.201101.exe
Translation: 0x0000 0x04b0

Trojan-PSW.Win32.Racealer.koa also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
FireEyeGeneric.mg.0f70ab202fe9257f
Qihoo-360Win32/TrojanSpy.Raccoon.HgIASOUA
CylanceUnsafe
Cybereasonmalicious.56f453
BitDefenderThetaGen:NN.ZevbaF.34804.Qm1@aeminxh
ESET-NOD32a variant of Win32/Injector.EOFI
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-PSW.Win32.Racealer.koa
F-SecureTrojan.TR/Injector.shqwk
SophosML/PE-A
WebrootW32.Malware.Gen
AviraTR/Injector.shqwk
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmTrojan-PSW.Win32.Racealer.koa
CynetMalicious (score: 100)
Acronissuspicious
VBA32TScope.Trojan.VB
MalwarebytesMalware.AI.2676739878
RisingMalware.Heuristic!ET#89% (RDMK:cmRtazreDL2Q4ThPwqJUeU4rws0g)
eGambitPE.Heur.InvalidSig
AVGWin32:Trojan-gen

How to remove Trojan-PSW.Win32.Racealer.koa?

Trojan-PSW.Win32.Racealer.koa removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment