Malware

Razy.574680 information

Malware Removal

The Razy.574680 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.574680 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Razy.574680?


File Info:

name: 9BBB8ED14EEEAF5C709E.mlw
path: /opt/CAPEv2/storage/binaries/e7d861ba70992537d62e756340cc04768507a13933715ab848dc903cce1bc0b1
crc32: 82822847
md5: 9bbb8ed14eeeaf5c709e7f461d2f4cf0
sha1: 2f7d0e5ca5327ff1f6211d4217e184fae202b705
sha256: e7d861ba70992537d62e756340cc04768507a13933715ab848dc903cce1bc0b1
sha512: 6212fd12e848267456f8cf793c45364c36f018c59aefb1a21da061a4566617c2095d2649d65ca04f5d3d6695359757ae5f8093631bf67384be062be73a0a0e90
ssdeep: 6144:JnpAm6qyBu2vukCUT8BsG0KwCkspuJ2ViKpxQX3Phe9:JulpqDwCkWG1KpxI0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B764BF4EF96B0827E7A341F76C6FA075EAB676A05558E0934DC22C3D74AF340843DE29
sha3_384: 2d6aa7aaff82ecdbd8bc71337d650639d5ba828ff668b26b8c14a7443416cb3f80dca5715954c5d1d9e3860390d06130
ep_bytes: 558bec81ecc0000000535657892ddceb
timestamp: 2012-05-04 11:38:02

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Solitaire Game Applet
FileVersion: 5.00.2138.1
InternalName: sol.exe
LegalCopyright: Copyright (C) Microsoft Corp. 1981-1999
OriginalFilename: sol.exe
ProductName: Microsoft(R) Windows (R) 2000 Operating System
ProductVersion: 5.00.2138.1
Translation: 0x0409 0x04b0

Razy.574680 also known as:

LionicTrojan.Win32.Generic.lw2L
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.574680
FireEyeGeneric.mg.9bbb8ed14eeeaf5c
CAT-QuickHealTrojanPWS.Zbot.Y
ALYacGen:Variant.Razy.574680
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.235932
SangforTrojan.Win32.Krap.iu
K7AntiVirusTrojan ( 004840d01 )
AlibabaTrojanPSW:Win32/Kryptik.8cc11200
K7GWTrojan ( 004840d01 )
Cybereasonmalicious.14eeea
VirITTrojan.Win32.Generic.YBL
CyrenW32/Zbot.DQ.gen!Eldorado
SymantecPacked.Generic.459
ESET-NOD32a variant of Win32/Kryptik.AFDO
APEXMalicious
KasperskyPacked.Win32.Krap.iu
BitDefenderGen:Variant.Razy.574680
NANO-AntivirusTrojan.Win32.Krap.btjlyd
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AvastWin32:Karagany
TencentMalware.Win32.Gencirc.114c435d
Ad-AwareGen:Variant.Razy.574680
EmsisoftGen:Variant.Razy.574680 (B)
ComodoTrojWare.Win32.Kryptik.ASR@4oc4x0
DrWebTrojan.PWS.Panda.1981
VIPRETrojan.Win32.Reveton.ca (v)
TrendMicroTROJ_AGENT_033710.TOMB
McAfee-GW-EditionPWS-Zbot.gen.bex
SophosMal/Generic-R + Mal/Zbot-KK
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Razy.574680
JiangminPacked.Krap.ejbe
WebrootW32.Infostealer.Zeus
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan[Packed]/Win32.Krap
ArcabitTrojan.Razy.D8C4D8
ZoneAlarmPacked.Win32.Krap.iu
MicrosoftPWS:Win32/Zbot!CI
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Zbot.R24471
Acronissuspicious
McAfeePWS-Zbot.gen.bex
MAXmalware (ai score=100)
VBA32BScope.TrojanPSW.Panda
TrendMicro-HouseCallTROJ_AGENT_033710.TOMB
RisingTrojan.Spy.Win32.Zbot.gac (CLOUD)
YandexTrojan.Kryptik!7MyiTzRyy1Y
IkarusTrojan-PWS.Win32.Zbot
eGambitPE.Heur.InvalidSig
FortinetW32/ZBOT.HL!tr
BitDefenderThetaGen:NN.ZexaF.34212.uq1@ae1Z0cki
AVGWin32:Karagany
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Packed.Krap.iu

How to remove Razy.574680?

Razy.574680 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment