Trojan

TrojanPSW.Pycoon removal

Malware Removal

The TrojanPSW.Pycoon is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanPSW.Pycoon virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Spanish (Colombia)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location

How to determine TrojanPSW.Pycoon?


File Info:

name: 0E66CC289A5963AB2933.mlw
path: /opt/CAPEv2/storage/binaries/63ff9cbbe33586017c27dbd3984adc264a500387230edca860f5875c708bbe80
crc32: E457ECF2
md5: 0e66cc289a5963ab2933c139f99266ff
sha1: 41914f6f1d648fb7ff8f2f3458bb2377824c10e0
sha256: 63ff9cbbe33586017c27dbd3984adc264a500387230edca860f5875c708bbe80
sha512: 4e9394c2a7272de0dd6f5336e3bbb240cadc523d5729c90801e7c2c4a47cf75a282f28e16d12917ce46232d2ca43cd7c8fe8ea6b835ad0c2e18a53014f39f8bc
ssdeep: 6144:Ylg+LfR8IbsaUjW8FgMeI7+dJCsMyR2MDkrZzzlA:Ylg+TR8XJg/w+dUsMyR27rpz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D5747D10BBA0C035E5F711F44AB9A268B53E7EE15B2450CB63D52BEE5A356E0EC3131B
sha3_384: d9e9c63db898c686ac4a68b4b0e965f3bdf067332a36b14501ac15798a4230bd06269dc2afb98a6e9820e6bbc6a5dae3
ep_bytes: 8bff558bece866ee0000e8110000005d
timestamp: 2021-02-06 18:06:13

Version Info:

0: [No Data]

TrojanPSW.Pycoon also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Pycoon.i!c
Elasticmalicious (high confidence)
ClamAVWin.Dropper.Tofsee-9932640-0
FireEyeGeneric.mg.0e66cc289a5963ab
McAfeePacked-GEE!0E66CC289A59
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/Raccrypt.1da87177
K7GWRiskware ( 0040eff71 )
CyrenW32/MSIL_Kryptik.GIF.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNWJ
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Ransom.Win32.Convagent.gen
BitDefenderTrojan.GenericKD.47811086
MicroWorld-eScanTrojan.GenericKD.47811086
AvastWin32:Malware-gen
TencentBackdoor.Win32.Tofsee.16000134
Ad-AwareTrojan.GenericKD.47811086
EmsisoftTrojan.GenericKD.47811086 (B)
DrWebTrojan.PWS.Stealer.31836
TrendMicroTrojan.Win32.SMOKELOADER.YXCADZ
McAfee-GW-EditionBehavesLike.Win32.MultiPlug.fh
SophosMal/Generic-R + Troj/Krypt-FV
IkarusTrojan.Win32
GDataWin32.Trojan.BSE.ZUWFTJ
AviraTR/AD.MalwareCrypter.fbqxg
KingsoftWin32.Troj.Generic_a.a.(kcloud)
GridinsoftRansom.Win32.Sabsik.ns
ArcabitTrojan.Generic.D2D98A0E
MicrosoftTrojan:Win32/Raccrypt.GY!MTB
AhnLab-V3Ransomware/Win.Stop.R462144
Acronissuspicious
ALYacTrojan.GenericKD.47811086
MAXmalware (ai score=84)
VBA32TrojanPSW.Pycoon
MalwarebytesTrojan.MalPack.GS
TrendMicro-HouseCallTrojan.Win32.SMOKELOADER.YXCADZ
RisingTrojan.Generic@ML.87 (RDMK:1ipAWa8MQko2iGpAxaJrKg)
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HNWJ!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove TrojanPSW.Pycoon?

TrojanPSW.Pycoon removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment