Malware

Should I remove “Razy.370762”?

Malware Removal

The Razy.370762 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.370762 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Collects and encrypts information about the computer likely to send to C2 server
  • Network activity detected but not expressed in API logs

Related domains:

wpad.local-net

How to determine Razy.370762?


File Info:

name: 7661B7A5DF690758B3ED.mlw
path: /opt/CAPEv2/storage/binaries/d75318bfe406e24af0929dec29cab193cd462b2faede1d72a0017b99a8534993
crc32: E362DD89
md5: 7661b7a5df690758b3ed44e676ad9ec7
sha1: efdda1c1fc36c16606a5c0a75e3b15aad383ad9e
sha256: d75318bfe406e24af0929dec29cab193cd462b2faede1d72a0017b99a8534993
sha512: d8bd3dce1c7425d006d3487b25515a40a91e80595f91fb8a2e6fea1cfd02bae0d8a1839f0668acca0169d40f36a11ae0680b8ca196be2e17c374c57b9dd08e73
ssdeep: 24576:zqLlIiETD9A0TVnW4rX4jnyr9tp096AONaueRaXWeFJEMD3:biyVd4Dyr93PaOzFu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1994523469BEC0F67E5F84EFDA124132A03A472662532DBCF4D4538B91C7A7A1E902DC7
sha3_384: 92ca94d8e8eb84d7b21ab31dccde56d6e987140989697126bfbd0124169839d5028894b22a361b88df35ce2649d082bb
ep_bytes: ff250020400000000000000000000000
timestamp: 2008-01-22 13:05:18

Version Info:

Translation: 0x0000 0x04b0
Comments: Archiving and Analysis of Tachograph Data
CompanyName: Softproject
FileDescription: TachoPlus.Archive
FileVersion: 1.21.7001.3867
InternalName: TachoPlus.Fleet.exe
LegalCopyright: 2005-2007 By Softproject
OriginalFilename: TachoPlus.Fleet.exe
ProductName: Tacho+Archive
ProductVersion: 1.21.7001.3867
Assembly Version: 1.21.7001.3867

Razy.370762 also known as:

LionicTrojan.MSIL.Crypt.4!c
MicroWorld-eScanGen:Variant.Razy.370762
FireEyeGen:Variant.Razy.370762
CAT-QuickHealTrojan.GenericFC.S6059913
McAfeeArtemis!7661B7A5DF69
CylanceUnsafe
SangforTrojan.MSIL.Generic.ky
K7AntiVirusTrojan ( 00526e131 )
AlibabaTrojan:MSIL/Generic.58d1ff7a
K7GWTrojan ( 00526e131 )
Cybereasonmalicious.5df690
ESET-NOD32a variant of Generik.IUOETHJ
APEXMalicious
KasperskyHEUR:Trojan.MSIL.Generic
BitDefenderGen:Variant.Razy.370762
NANO-AntivirusTrojan.Win32.Crypt.exoboe
AvastWin32:Malware-gen
TencentMsil.Trojan.Crypt.Ahen
Ad-AwareGen:Variant.Razy.370762
SophosMal/Generic-S
ZillyaTrojan.Crypt.Win32.40864
TrendMicroTROJ_GEN.R002C0WIO21
McAfee-GW-EditionArtemis!Trojan
EmsisoftGen:Variant.Razy.370762 (B)
IkarusTrojan.MSIL.Crypt
GDataGen:Variant.Razy.370762
JiangminTrojan.MSIL.iehh
Antiy-AVLTrojan/Generic.ASMalwS.23F5F0D
ArcabitTrojan.Razy.D5A84A
MicrosoftTrojan:Win32/Wacatac.B!ml
ALYacGen:Variant.Razy.370762
MAXmalware (ai score=81)
VBA32Trojan.MSIL.Crypt
MalwarebytesMachineLearning/Anomalous.100%
TrendMicro-HouseCallTROJ_GEN.R002C0WIO21
MaxSecureTrojan.Malware.11196064.susgen
FortinetW32/Crypt.DVDJ!tr
AVGWin32:Malware-gen

How to remove Razy.370762?

Razy.370762 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment