Adware

What is “Adware.Razy.873682”?

Malware Removal

The Adware.Razy.873682 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Razy.873682 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the shellcode get eip malware family
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Collects information to fingerprint the system
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Adware.Razy.873682?


File Info:

name: C76AEB7116D6E7BC325D.mlw
path: /opt/CAPEv2/storage/binaries/1c9bd9f96b583ef76ba672d7bed419d5f49ea945fe29c29a9d5d9c4f880c543c
crc32: 136EAD37
md5: c76aeb7116d6e7bc325d769ddcaeddb8
sha1: 53e0cf85e4c9f53dc57f62eee36c85bfe4a88aa3
sha256: 1c9bd9f96b583ef76ba672d7bed419d5f49ea945fe29c29a9d5d9c4f880c543c
sha512: 6bbd5195e3830adaa3fd727ffa556ef100f1b26073344a09e2a3dc30561f2f982903f37fe648286475d5a723f59ddd67815dd16ad99d4f4e46aed3976daa908f
ssdeep: 3072:dK2Q/BG45mkbQ0ybi4XgY65G/Uw3L0rrpIctC2FqvEhv+Th62b45:djGG44ime5G/Uwwr+NQm45
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B0355B223361642AE3AEC7B80460D76E5FD77E12A77B375A1518F3749AF04CF1C4258A
sha3_384: aeaad78a1af71804906f4e03f7fc292ec8cbf2fbb5147770a646164c2bab27a35c5a42e7e154b6afb1549c691dfc8bb6
ep_bytes: e827030000e985feffff558bec56ff75
timestamp: 2018-05-06 20:30:39

Version Info:

0: [No Data]

Adware.Razy.873682 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
ClamAVWin.Malware.Razy-6911718-0
CAT-QuickHealPUA.AdposhelPMF.S19361443
SkyhighBehavesLike.Win32.Infected.tz
ALYacGen:Variant.Adware.Razy.873682
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Adware.Razy.873682
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005378b01 )
BitDefenderGen:Variant.Adware.Razy.873682
K7GWTrojan ( 005378b01 )
CrowdStrikewin/grayware_confidence_100% (W)
ArcabitTrojan.Adware.Razy.DD54D2
BitDefenderThetaAI:Packer.CB5BB3981E
VirITAdware.Win32.ApoShel.M
SymantecPUA.Downloader
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Adware.Adposhel.BM
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:AdWare.Win32.Adposhel.owhx
AlibabaAdWare:Win32/Adposhel.f01fa21d
NANO-AntivirusTrojan.Win32.Adposhel.fdeeob
ViRobotTrojan.Win32.Adposhel.Gen.A
MicroWorld-eScanGen:Variant.Adware.Razy.873682
RisingAdware.Adposhel!1.B29D (CLASSIC)
EmsisoftApplication.Downloader (A)
F-SecureAdware.ADWARE/Adware.Gen8
DrWebTrojan.DownLoader26.48672
ZillyaAdware.AdposhelGen.Win32.4
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.c76aeb7116d6e7bc
SophosAdposhel (PUA)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.Adposhel.qrg
VaristW32/Emotet.GU.gen!Eldorado
AviraADWARE/Adware.Gen8
MAXmalware (ai score=65)
Antiy-AVLGrayWare[AdWare]/Win32.Adposhel.bb
XcitiumApplication.Win32.AdWare.Adposhel.BB@7ohhmx
MicrosoftAdware:Win32/Adposhel
SUPERAntiSpywareAdware.Adposhel/Variant
ZoneAlarmnot-a-virus:AdWare.Win32.Adposhel.owhx
GDataGen:Variant.Adware.Razy.873682
GoogleDetected
AhnLab-V3PUP/Win32.Adposhel.R229425
Acronissuspicious
McAfeeGenericRXFP-IB!C76AEB7116D6
DeepInstinctMALICIOUS
VBA32OScope.Malware-Cryptor.Kidep
Cylanceunsafe
PandaTrj/Genetic.gen
TencentAdWare.Win32.Adposhel.ha
YandexTrojan.GenAsa!6lOqslBfUMI
IkarusPUA.Adposhel
MaxSecureAdware.RAZY.296399
FortinetAdware/Adposhel
AVGWin32:AdwareX-gen [Adw]
Cybereasonmalicious.116d6e
AvastWin32:AdwareX-gen [Adw]

How to remove Adware.Razy.873682?

Adware.Razy.873682 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment