Trojan

How to remove “Trojan.Raccoon”?

Malware Removal

The Trojan.Raccoon is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Raccoon virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Divehi
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

api.2ip.ua

How to determine Trojan.Raccoon?


File Info:

crc32: 06814074
md5: 5707169bd74219d3f8a05e5476dbd53e
name: 5707169BD74219D3F8A05E5476DBD53E.mlw
sha1: 93d01022e6e2a8f8ad96bac129783717a7331215
sha256: eac0eb5f82b2750b783ca8a1810986cbcc224f37901a97402c9f9b349f8d1aac
sha512: 4b47ba08c2268ce5f3593dcbcfdb6b5a5e75df563b5171c0271ebb2a1691f0a1d6f9b324bd22f2ad5bca93961b74e399a242d1d32691d336f37166b664c0cb22
ssdeep: 24576:/x70Zu+BI3QhYShGku3pI+MiEwLGW+75h7SWn:/x7pWgnFpMi5LGW+
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translations: 0x0522 0x023c

Trojan.Raccoon also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0058a5be1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Raccoon
ALYacTrojan.Ransom.Stop
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 0058a5be1 )
Cybereasonmalicious.2e6e2a
BaiduWin32.Trojan.Kryptik.jm
CyrenW32/Kryptik.FSC.gen!Eldorado
SymantecPacked.Generic.620
ESET-NOD32a variant of Win32/Kryptik.HNHU
APEXMalicious
AvastWin32:DropperX-gen [Drp]
KasperskyHEUR:Trojan-Ransom.Win32.Stop.gen
BitDefenderTrojan.GenericKDZ.80106
MicroWorld-eScanTrojan.GenericKDZ.80106
TencentWin32.Trojan.Stop.Stkh
Ad-AwareTrojan.GenericKDZ.80106
SophosML/PE-A + Troj/Krypt-DY
TrendMicroRansom_Stop.R011C0DKJ21
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.5707169bd74219d3
EmsisoftTrojan.GenericKDZ.80106 (B)
JiangminTrojan.Stop.ckp
AviraHEUR/AGEN.1145785
eGambitUnsafe.AI_Score_86%
MicrosoftTrojan:Win32/Raccoon.AD!MTB
GDataTrojan.GenericKDZ.80106
AhnLab-V3Downloader/Win.BeamWinHTTP.R450247
Acronissuspicious
McAfeePacked-GDV!5707169BD742
MAXmalware (ai score=81)
VBA32BScope.Trojan.Sabsik.FL
MalwarebytesTrojan.MalPack.GS
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_Stop.R011C0DKJ21
RisingMalware.Heuristic!ET#90% (RDMK:cmRtazp3piaoGIKWqgvY7ZbDLAbG)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.FNRJ!tr
AVGWin32:DropperX-gen [Drp]

How to remove Trojan.Raccoon?

Trojan.Raccoon removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment