Malware

Razy.674154 (file analysis)

Malware Removal

The Razy.674154 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.674154 virus can do?

  • Presents an Authenticode digital signature
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX

How to determine Razy.674154?


File Info:

crc32: CC1A5CFB
md5: bb91272a7606c288eb024c67d4fef2d3
name: BB91272A7606C288EB024C67D4FEF2D3.mlw
sha1: 491e195bd47eb1db8f7a4f67cd93a03b61bee005
sha256: c746995bb8750ce537bf970d3fee87423aca1101da549d871738183e1c16a3dd
sha512: edb257358b98f088b6f6c233c426ea40e577950625e74b19ae0fd4741ed458920ae2c1a547c795aff4f987f5eeec520794cbcfe612cc762be4d41318ec0029ac
ssdeep: 768:Z1f07uX579b/lguOuFoB4pmJz99UzIkVgJIODTbxrOU:Z1c7U57gnu8nJB9UzIkVgPXpOU
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: x8f6fx4ef6x4ec5x4f9bx6280x672fx4ea4x6d41xff0cx8bf7x52ffx7528x4e8ex5546x4e1ax53cax975ex6cd5x7528x9014xff0cx5982x4ea7x751fx6cd5x5f8bx7ea0x7eb7x4e0ex672cx4ebax65e0x5173
InternalName: xing
FileVersion: 4.0.1.2
CompanyName: xing
LegalTrademarks: xing
ProductName: xing
ProductVersion: 4.0.1.2
FileDescription: xing
OriginalFilename: xing
Translation: 0x0804 0x0000

Razy.674154 also known as:

ALYacGen:Variant.Razy.674154
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderGen:Variant.Razy.674154
Cybereasonmalicious.a7606c
ESET-NOD32a variant of Win32/Packed.BlackMoon.A potentially unwanted
TotalDefenseWin32/Oflwr.A!crypt
ClamAVWin.Dropper.Tiggre-9845940-0
MicroWorld-eScanGen:Variant.Razy.674154
Ad-AwareGen:Variant.Razy.674154
SophosGeneric PUA EJ (PUA)
BitDefenderThetaGen:NN.ZexaF.34628.cmMfa4hqXxlb
McAfee-GW-EditionGenericRXMA-QI!A8DB428218DA
FireEyeGen:Variant.Razy.674154
EmsisoftGen:Variant.Razy.674154 (B)
SentinelOneStatic AI – Malicious PE
MicrosoftProgram:Win32/Wacapew.C!ml
GridinsoftTrojan.Win32.Packed.dd!n
ArcabitTrojan.Razy.DA496A
GDataWin32.Trojan.Agent.WP
AhnLab-V3Malware/Win32.Generic.C4364621
McAfeeArtemis!BB91272A7606
MAXmalware (ai score=86)
VBA32BScope.Trojan.Wacatac
MalwarebytesMalware.AI.630807843
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002H06CL21
IkarusAdWare.Win32.BlackMoon
FortinetW32/Agent.WP!tr
Qihoo-360Win32/Trojan.Generic.HgIASRMA

How to remove Razy.674154?

Razy.674154 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment