Trojan

Trojan:Win32/Raccoon!pz removal guide

Malware Removal

The Trojan:Win32/Raccoon!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Raccoon!pz virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Trojan:Win32/Raccoon!pz?


File Info:

name: 74187CC016E25D749F5E.mlw
path: /opt/CAPEv2/storage/binaries/ec22fc83950a4c963bb6bd8f3f600455c9c1282ab36b949ee2c3e7cb0517096a
crc32: 6A29BE88
md5: 74187cc016e25d749f5e54bd973843ef
sha1: 5ed7355b572ec1029d42a8e9b1a505bf0246e76c
sha256: ec22fc83950a4c963bb6bd8f3f600455c9c1282ab36b949ee2c3e7cb0517096a
sha512: 7d869ab883f3613998d256368514eddb5b9d181e81ec17934ac4c6c7ef5ddbb8a3430128e8f5dbfccf285c26d3cf4d2596f416af3dd03f8236b0c9a4dd88e918
ssdeep: 12288:/xArSdeP8mBg0+IHWxrc3fbELtbqFJxoUyOWbCijCU5uMboEd6Cy:5ArSdePcU2O3ItCJCUFgCijV8MoTCy
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T12DD49D64D61068ECF52A5E3837DAF5B548DD693023063083B9EBDF4B21B8795933863B
sha3_384: b18086bf258f66800ff181eec1a0de73fab48ec928f653a30d9f0a60639a8b92f689625785ca465e92e3144186a10804
ep_bytes: 5150528d0d18000000648b0101c801c8
timestamp: 2087-01-20 22:38:09

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Windows Command Processor
FileVersion: 10.0.15063.0 (WinBuild.160101.0800)
InternalName: cmd
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: Cmd.Exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 10.0.15063.0
Translation: 0x0409 0x04b0

Trojan:Win32/Raccoon!pz also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Expiro.n!c
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Expiro.Gen.6
FireEyeGeneric.mg.74187cc016e25d74
CAT-QuickHealW32.Expiro.R4
SkyhighBehavesLike.Win32.Virut.jc
McAfeeTrojan-FUNU!74187CC016E2
Cylanceunsafe
VIPREWin32.Expiro.Gen.6
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 0059e5471 )
BitDefenderWin32.Expiro.Gen.6
K7GWVirus ( 0059e5471 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitWin32.Expiro.Gen.6
VirITWin32.Expiro.CV
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Expiro.CP
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Virus.Expiro-9930674-0
KasperskyVirus.Win32.Expiro.ns
AlibabaVirus:Win32/Expiro.3412b3c0
NANO-AntivirusVirus.Win32.Gen.ccmw
RisingVirus.Expiro!8.375 (CLOUD)
SophosMal/EncPk-MK
F-SecureTrojan.TR/Patched.Gen
DrWebWin32.Expiro.150
Trapminemalicious.high.ml.score
EmsisoftWin32.Expiro.Gen.6 (B)
IkarusVirus.Win32.Expiro
JiangminTrojan.PSW.Stealer.abj
VaristW32/Expiro.AN.gen!Eldorado
AviraTR/Patched.Gen
Antiy-AVLVirus/Win32.Expiro.ndg
MicrosoftTrojan:Win32/Raccoon!pz
ZoneAlarmVirus.Win32.Expiro.ns
GDataWin32.Expiro.Gen.6
GoogleDetected
AhnLab-V3Virus/Win.Expiro.X2160
ALYacWin32.Expiro.Gen.6
MAXmalware (ai score=82)
DeepInstinctMALICIOUS
VBA32BScope.Trojan.Wacatac
MalwarebytesGeneric.Malware/Suspicious
PandaGeneric Suspicious
TencentWin32.Virus.Expiro.Dwnw
SentinelOneStatic AI – Malicious PE
FortinetW32/Expiro.NDG
AVGWin32:Xpirat-C [Inf]
Cybereasonmalicious.b572ec
AvastWin32:Xpirat-C [Inf]

How to remove Trojan:Win32/Raccoon!pz?

Trojan:Win32/Raccoon!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment