Malware

What is “Razy.664294”?

Malware Removal

The Razy.664294 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.664294 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • .NET file is packed/obfuscated with SmartAssembly
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Razy.664294?


File Info:

name: 98889FA7A9A5974442FF.mlw
path: /opt/CAPEv2/storage/binaries/d0eb0244f0600fd228654f27cef5e7d8bd848e462bf1f47576c349ca60b471e6
crc32: 43B3FA9E
md5: 98889fa7a9a5974442ff5cd6e569b260
sha1: 6f1ce9348697781b15e33193e82ff03452951d0f
sha256: d0eb0244f0600fd228654f27cef5e7d8bd848e462bf1f47576c349ca60b471e6
sha512: a326d233dd29f64122fd0f7c0da9861b11111142da8d476079d5c43f0b60fb22ff59dd457db8807cc2e2050d3b5454ee3aa80fadf38d70335de5027d26a76859
ssdeep: 6144:fjkfmrdnlWCb2TQDArbOX6rxACU072hkeXdnPSFnfv5zXkymsTUCrl7:LmmrdlWVmAf++xAf07kkeXdnPSFnfv5x
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A9646C5933C28E1AE39E12B5C0A109607B78DC13FAC9E34F9A4C39D219777E5C1DA887
sha3_384: ca2f2e0d6bc20eea542f9abd4d27d96633605ed30497cf993069ac57d6e07674335fde0c3770317602d69536aac8f1ad
ep_bytes: ff254c31430000005f436f724578654d
timestamp: 2012-10-10 22:09:00

Version Info:

Translation: 0x0000 0x04b0
Comments: Windows application
FileDescription: explore
FileVersion: 1.4.7.7
InternalName: explo.exe
LegalCopyright: Microsoft Corporation
OriginalFilename: explo.exe
ProductVersion: 1.4.7.7
Assembly Version: 0.0.0.0

Razy.664294 also known as:

LionicTrojan.Win32.Generic.lZG8
MicroWorld-eScanGen:Variant.Razy.664294
ClamAVWin.Packed.Generic-9808464-0
ALYacGen:Variant.Razy.664294
CylanceUnsafe
VIPREGen:Variant.Razy.664294
K7AntiVirusSpyware ( 0055e3ec1 )
AlibabaTrojan:MSIL/Generic.8549776c
K7GWSpyware ( 0055e3ec1 )
Cybereasonmalicious.7a9a59
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Spy.RinLog.A
APEXMalicious
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Razy.664294
NANO-AntivirusTrojan.Win32.RinLog.cyndqn
TencentWin32.Trojan.Generic.Qimw
Ad-AwareGen:Variant.Razy.664294
SophosMal/Generic-S
ComodoMalware@#3rcl9o6oor2jr
ZillyaTrojan.RinLog.Win32.22
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.98889fa7a9a59744
EmsisoftGen:Variant.Razy.664294 (B)
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Razy.664294
Antiy-AVLTrojan/Win32.AGeneric
ArcabitTrojan.Razy.DA22E6
ZoneAlarmUDS:DangerousObject.Multi.Generic
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
MAXmalware (ai score=100)
RisingSpyware.RinLog!8.943 (CLOUD)
YandexTrojan.Agent!q0/D/6iPhiE
IkarusTrojan-Dropper.MSIL
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Generic!tr
BitDefenderThetaGen:NN.ZemsilF.34698.tm0@a00WBJp
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Razy.664294?

Razy.664294 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment