Trojan

VHO:Trojan-PSW.Win32.Stealer.kcn removal instruction

Malware Removal

The VHO:Trojan-PSW.Win32.Stealer.kcn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VHO:Trojan-PSW.Win32.Stealer.kcn virus can do?

  • Presents an Authenticode digital signature
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine VHO:Trojan-PSW.Win32.Stealer.kcn?


File Info:

crc32: 0E80DBF1
md5: e9fab15aa8c82680b4e442f1f61e99be
name: E9FAB15AA8C82680B4E442F1F61E99BE.mlw
sha1: c8a146cc3b35c14a5dcc4ba7a85b8865817e4ccc
sha256: d8c89529c7fa6c3a1ea6969d30935cfe39b00e96a97eeae1742f882ff407f600
sha512: 478f58ccb5bd7fd711f9f9610db1850f149d0353cc94dfd50c7f22f12dad5aba96a1e77af0f87397b1a75d35eb0e72317b4b0760f8e5319417a5aaa678a2e432
ssdeep: 12288:/Q0ifmMJz7bLg0EKsWmAhndfnZs8svfozjC:MFeQsWmAhBIvfozjC
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2020
Assembly Version: 1.0.0.0
InternalName: Svc_host.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: Svc_host
ProductVersion: 1.0.0.0
FileDescription: Svc_host
OriginalFilename: Svc_host.exe

VHO:Trojan-PSW.Win32.Stealer.kcn also known as:

Elasticmalicious (high confidence)
ClamAVWin.Malware.Razy-9889631-0
ALYacGen:Variant.Razy.914220
CylanceUnsafe
SangforVirus.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
BitDefenderGen:Variant.Razy.914220
Cybereasonmalicious.c3b35c
ESET-NOD32a variant of Win32/Packed.Enigma.FH
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Trojan-PSW.Win32.Stealer.kcn
MicroWorld-eScanGen:Variant.Razy.914220
Ad-AwareGen:Variant.Razy.914220
SophosGeneric ML PUA (PUA)
BitDefenderThetaGen:NN.ZemsilF.34126.Gy2@a8luvAo
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.e9fab15aa8c82680
EmsisoftTrojan-Spy.Agent (A)
SentinelOneStatic AI – Malicious PE
eGambitTrojan.Generic
MicrosoftTrojan:Script/Phonzy.C!ml
GridinsoftTrojan.Heur!.01012031
ArcabitTrojan.Razy.DDF32C
GDataWin32.Trojan.PSE.1MFCAJH
AhnLab-V3Trojan/Win.Generic.C4611711
Acronissuspicious
McAfeeArtemis!E9FAB15AA8C8
MAXmalware (ai score=89)
MalwarebytesSpyware.PasswordStealer
PandaTrj/Genetic.gen
FortinetW32/Agent.EF41!tr

How to remove VHO:Trojan-PSW.Win32.Stealer.kcn?

VHO:Trojan-PSW.Win32.Stealer.kcn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment