Trojan

Should I remove “Trojan.RaccoonPMF.S26406850”?

Malware Removal

The Trojan.RaccoonPMF.S26406850 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.RaccoonPMF.S26406850 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Greek
  • Authenticode signature is invalid
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization

How to determine Trojan.RaccoonPMF.S26406850?


File Info:

name: 507E0F97AA141FC11AD9.mlw
path: /opt/CAPEv2/storage/binaries/da726ad6fc094594bafeff75a082f23e7c42cf43b2ca3b5a1492e403fdc2807a
crc32: E20F6F06
md5: 507e0f97aa141fc11ad932d5141fb4f8
sha1: 066fdfc77c4a00a061635ffea92a8ab3b3859021
sha256: da726ad6fc094594bafeff75a082f23e7c42cf43b2ca3b5a1492e403fdc2807a
sha512: 754492e1e897f69ffb7ab14281ef9af00a99ca303e88897da67687d67811801c75f556d5c31702c1925fe41605e34182d209b79162dee33ac59c1a8ebddf4040
ssdeep: 3072:84+SKLlhgq5mr5OBt8fGD4D6VZ61hM/h3Lfed:84pKLlhVR8GD4GVZON
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C244BF71F680C431D48616B06826CFE11ABDBC32DB55866737A82B5EAF323D0562735F
sha3_384: 95e209459a002748146540d1744547aa8a0befd1362361da9a71ff4ad57d232862f3bbab671dd7287a468fff25e8a5a0
ep_bytes: e8bd380000e979feffffcccccccccccc
timestamp: 2020-09-30 03:56:33

Version Info:

FileVersion: 21.29.111.69
InternationalName: bomgveoci.iwa
Copyright: Copyrighz (C) 2021, fudkorta
ProjectVersion: 1.10.74.57
Translations: 0x0121 0x03ca

Trojan.RaccoonPMF.S26406850 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Stop.j!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.48064733
FireEyeGeneric.mg.507e0f97aa141fc1
CAT-QuickHealTrojan.RaccoonPMF.S26406850
ALYacTrojan.GenericKD.48064733
CylanceUnsafe
ZillyaTrojan.Smokeloader.Win32.709
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0053d5971 )
K7GWTrojan ( 0058d5ee1 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Qbot.FK.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Smokeloader.F
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Mikey-9917879-0
KasperskyHEUR:Trojan-Ransom.Win32.Stop.gen
BitDefenderTrojan.GenericKD.48064733
AvastWin32:AceCrypter-C [Cryp]
RisingRansom.Stop!8.10810 (CLOUD)
Ad-AwareTrojan.GenericKD.48064733
SophosMal/Generic-S + Mal/Agent-AWV
ComodoMalware@#38q08omk8aznh
DrWebTrojan.PWS.Stealer.32103
TrendMicroTROJ_GEN.R002C0PAN22
McAfee-GW-EditionBehavesLike.Win32.Generic.dm
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.BSE.13HKEPU
JiangminTrojan.Stop.cuj
AviraHEUR/AGEN.1242353
Antiy-AVLTrojan/Generic.ASMalwS.3512E60
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftRansom.Win32.STOP.sa
ZoneAlarmHEUR:Trojan-Ransom.Win32.Stop.gen
MicrosoftRansom:Win32/StopCrypt.PAR!MTB
CynetMalicious (score: 100)
AhnLab-V3Infostealer/Win.SmokeLoader.R467547
McAfeePacked-GEE!507E0F97AA14
MAXmalware (ai score=89)
VBA32TrojanSpy.Lpxenur
MalwarebytesTrojan.MalPack
TrendMicro-HouseCallTROJ_GEN.R002C0PAN22
TencentTrojan-ransom.Win32.Stop.16000284
YandexTrojan.Smokeloader!SgOrylHxJCw
IkarusTrojan-Ransom.StopCrypt
FortinetW32/GenericKDZ.6DF1!tr
BitDefenderThetaGen:NN.ZexaF.34232.pq0@a4t57QoG
AVGWin32:AceCrypter-C [Cryp]
Cybereasonmalicious.77c4a0
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.RaccoonPMF.S26406850?

Trojan.RaccoonPMF.S26406850 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment