Malware

Razy.473688 removal guide

Malware Removal

The Razy.473688 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.473688 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Sample contains Overlay data
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Checks for the presence of known windows from debuggers and forensic tools
  • Checks for the presence of known windows from debuggers and forensic tools

How to determine Razy.473688?


File Info:

name: A74AB6BF7073A025658F.mlw
path: /opt/CAPEv2/storage/binaries/58f3b013b2df97fb3066b5a3049104a57a28b6cdf2bf7908df3a6dad296eedb3
crc32: 219D915A
md5: a74ab6bf7073a025658f7096f621f8e6
sha1: e17655d17bf743bac8307d0886c5d58f51c428c4
sha256: 58f3b013b2df97fb3066b5a3049104a57a28b6cdf2bf7908df3a6dad296eedb3
sha512: a37f858d909a47ff5f3496d026cc857537c24d3a72a9fa082b2ca3045f075f018b3d2dbedae3feeea74e429644627c578776c7d13eb23f1e32aff8356753935c
ssdeep: 12288:xr+9mPWsxhv+IOYc5UHoS9Fyk4xLeesOx2pLTwoV:dhaUH2DxLUpLMQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10EA49D30B673E432D8A184F44D3DEE56352DAD180F654EFB73D82A3A69710D11B32EA6
sha3_384: 24ca55b25e8973515c995c0279a3f6751be4cabda85818b11540dc2760e5ad3d1e40c056509c7540548fabc1663d7873
ep_bytes: e8fb0c0000e97afeffff558beca1b800
timestamp: 2022-07-05 19:45:11

Version Info:

0: [No Data]

Razy.473688 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Razy.4!c
MicroWorld-eScanGen:Variant.Razy.473688
FireEyeGeneric.mg.a74ab6bf7073a025
ALYacGen:Variant.Razy.473688
CylanceUnsafe
ZillyaTrojan.Agent.Win32.2827564
SangforInfostealer.Win32.Agent.Vyfg
K7AntiVirusPassword-Stealer ( 005943421 )
AlibabaTrojanPSW:Win32/Generic.605c4e75
K7GWPassword-Stealer ( 005943421 )
Cybereasonmalicious.f7073a
BitDefenderThetaGen:NN.ZexaF.34806.DuX@aygLGBfi
CyrenW32/ABRisk.BSLF-9201
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/PSW.Agent.OOU
TrendMicro-HouseCallTROJ_GEN.R002H0CGB22
Paloaltogeneric.ml
BitDefenderGen:Variant.Razy.473688
NANO-AntivirusTrojan.Win32.Razy.jpzxvh
AvastWin32:Trojan-gen
Ad-AwareGen:Variant.Razy.473688
EmsisoftGen:Variant.Razy.473688 (B)
VIPREGen:Variant.Razy.473688
McAfee-GW-EditionBehavesLike.Win32.Generic.gh
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
IkarusTrojan-PSW.Agent
GDataWin32.Trojan.PSE.JE66CN
AviraTR/PSW.Agent.fpwff
Antiy-AVLTrojan/Generic.ASMalwS.720E
ArcabitTrojan.Razy.D73A58
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.PWS.C5196586
McAfeeGenericRXTQ-GQ!A74AB6BF7073
MAXmalware (ai score=89)
VBA32BScope.Trojan.APosT
MalwarebytesMalware.AI.290102393
APEXMalicious
RisingTrojan.Generic@AI.100 (RDML:9S25A+5NNfmV1oop8Cma+w)
YandexTrojan.PWS.Agent!fI1AUjTmtvM
MaxSecureTrojan.Malware.109147633.susgen
FortinetW32/PossibleThreat
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Razy.473688?

Razy.473688 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment