Trojan

VHO:Trojan-PSW.Win32.Racealer.mpk information

Malware Removal

The VHO:Trojan-PSW.Win32.Racealer.mpk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VHO:Trojan-PSW.Win32.Racealer.mpk virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

How to determine VHO:Trojan-PSW.Win32.Racealer.mpk?


File Info:

crc32: 489B47A8
md5: 38bdf4ae49c35f0ccf7e6820d2f9db52
name: 38BDF4AE49C35F0CCF7E6820D2F9DB52.mlw
sha1: 8a4eb8a513b03b26d10e58a8a0763cb1353887be
sha256: eb77f172afe361c9ff6138ae480d05a5832ba5c15191f9a9b5ccb1267ca5ed5c
sha512: 62038c2ba5e0abe80397a41913ffa567839ec1eaa87a5a0906f870e36b5e2361ec5f1a5688342bc7673a2baadaa0b8b9fb2977166cee1884f8d1f55633582693
ssdeep: 24576:+jG34D1gDl/fBY9uHLwr0TbPVe7tvG7M+QfyEBhi+O5OrDHA6tzlkEaHNYK3r1ZS:+jG34+DBfBuurwp7A0hif5iAmlNaxPQF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 1998-2021 VMware, Inc.
InternalName: vmui
FileVersion: 16.1.2 build-17966106
CompanyName: VMware, Inc.
ProductName: VMware Workstation
ProductVersion: 16.1.2 build-17966106
FileDescription: VMware Workstation
OriginalFilename: vmware.exe
Translation: 0x0409 0x04b0

VHO:Trojan-PSW.Win32.Racealer.mpk also known as:

CylanceUnsafe
ESET-NOD32a variant of MSIL/Spy.Agent.DFY
APEXMalicious
KasperskyVHO:Trojan-PSW.Win32.Racealer.mpk
SophosGeneric ML PUA (PUA)
BitDefenderThetaGen:NN.ZexaF.34294.M52aaS68NWii
SentinelOneStatic AI – Suspicious PE
eGambitPE.Heur.InvalidSig
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GridinsoftTrojan.Heur!.012120B1
McAfeeAgentTesla-FDFF!38BDF4AE49C3
VBA32BScope.Backdoor.Agent
MalwarebytesSpyware.PasswordStealer
YandexTrojan.GenAsa!CKhYg8AywSM

How to remove VHO:Trojan-PSW.Win32.Racealer.mpk?

VHO:Trojan-PSW.Win32.Racealer.mpk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment