Malware

What is “Razy.403674”?

Malware Removal

The Razy.403674 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.403674 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family

How to determine Razy.403674?


File Info:

name: BAEEDFC6F9C5FFBBFCC4.mlw
path: /opt/CAPEv2/storage/binaries/06a2cc6875b1c1d68dfd10ffa288525d4aef91bccc5e15bfca31c648df2e7f58
crc32: F6BFE0D2
md5: baeedfc6f9c5ffbbfcc4d0bc9911b41c
sha1: 39808ed40394262cc9323127d8d949357323767b
sha256: 06a2cc6875b1c1d68dfd10ffa288525d4aef91bccc5e15bfca31c648df2e7f58
sha512: 717d263f6f1d28150497b57edf19dbc97b26c5adaeae043ef4a2977868b7ed02de5d7bd9e8eb7b1daa62e39643f2adcf158f521bcbd33735372d5fcb8d093283
ssdeep: 1536:89JU+S5tnCvvH/RNJ5YOkJK4gtaIeZRwoFvarVm0azAi2:89J0nCXZb5zkVeaImRwBrVmL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F414E0CED1ABBCD3F9DF1B3D600368ADE266751C35FC8952A3848CEAF5E561012D8189
sha3_384: 1afcbf4d4e82eb57a6a12fa13de6be34c8e58be4bb70884e3fe20cf088f62b03f561eb290f06d13e81b22ae4f7f00829
ep_bytes: 4c24a48bcd8b5424a4810a0329124566
timestamp: 1988-05-31 10:21:08

Version Info:

0: [No Data]

Razy.403674 also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.Allaple.mzMC
Elasticmalicious (high confidence)
DrWebTrojan.Packed2.44603
MicroWorld-eScanGen:Variant.Razy.403674
ClamAVWin.Worm.Allaple-5
FireEyeGeneric.mg.baeedfc6f9c5ffbb
CAT-QuickHealW32.Virut.Cur1
SkyhighBehavesLike.Win32.RAHack.dt
ALYacGen:Variant.Razy.403674
Cylanceunsafe
ZillyaWorm.Allaple.Win32.1
SangforSuspicious.Win32.Save.a
K7AntiVirusNetWorm ( f10000011 )
AlibabaVirus:Win32/Virut.17a223de
K7GWNetWorm ( f10000011 )
Cybereasonmalicious.403942
BitDefenderThetaGen:NN.ZexaF.36680.muW@aOHITfj
VirITWorm.Win32.Allaple.DQB
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.GECN
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Virut.ce
BitDefenderGen:Variant.Razy.403674
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:Agent-BARL [Trj]
TencentWorm.Win32.Allple.ya
EmsisoftGen:Variant.Razy.403674 (B)
F-SecureNet-Worm:W32/Allaple.gen!B
BaiduWin32.Trojan.Kryptik.gf
VIPREGen:Variant.Razy.403674
TrendMicroWORM_ALLAPLE.IK
Trapminemalicious.moderate.ml.score
CMCVirus.Win32.Virut.1!O
SophosMal/Generic-S
IkarusNet-Worm.Win32.Allaple.a
GDataGen:Variant.Razy.403674
WebrootW32.Worm.A
GoogleDetected
AviraWORM/Patched.Ren.Gen
Antiy-AVLGrayWare/Win32.Allaple.gen
Kingsoftmalware.kb.a.1000
XcitiumNetWorm.Win32.Allaple.GEN@1ei64a
ArcabitTrojan.Razy.D628DA
ZoneAlarmVirus.Win32.Virut.ce
MicrosoftVirus:Win32/Madang.A!dam
VaristW32/Allaple.A.gen!Eldorado
AhnLab-V3Win-Trojan/Starman.Gen
Acronissuspicious
MAXmalware (ai score=83)
MalwarebytesAllaple.Worm.NetWorm.DDS
PandaGeneric Suspicious
TrendMicro-HouseCallWORM_ALLAPLE.IK
RisingWorm.Allaple!1.AB29 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Allaple.gen!tr
AVGWin32:Agent-BARL [Trj]
DeepInstinctMALICIOUS

How to remove Razy.403674?

Razy.403674 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment