Malware

Should I remove “Razy.698093 (B)”?

Malware Removal

The Razy.698093 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.698093 (B) virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (7 unique times)
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Checks for the presence of known windows from debuggers and forensic tools
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Detects VirtualBox through the presence of a registry key
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system

Related domains:

bit.do
rebrand.ly
jamshed.pk
backgrounds.pk
karimgousa.ug
karimgouss.ug
telete.in
mazoyer.ac.ug
mazooyaar.ac.ug
apps.identrust.com

How to determine Razy.698093 (B)?


File Info:

crc32: EC575949
md5: b556526e3da710a1bdf1d8f27b75feaf
name: B556526E3DA710A1BDF1D8F27B75FEAF.mlw
sha1: c7d412bef31e46c9bb9facbe37eb6862ce38ea63
sha256: 37e292496f057cbbba45f28b7510c8e4b555dcb2ad4308e1df9f251c9980830d
sha512: f87e4695bc2f24bb7754a33d534a88fefe9dd06df3a50bd930456279bf100330139ada22f5b4a423ab1aa807ec5e8c456a917ae9eb472f787103400c330803df
ssdeep: 6144:Ti2gMUk7PDUnsIVbk5ofoSM7NbjI0yZdBu4H:Ti20E4sIa4oSe5su4
type: PE32 executable (console) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Razy.698093 (B) also known as:

K7AntiVirusBackdoor ( 00557edb1 )
DrWebTrojan.Siggen9.55566
ClamAVWin.Trojan.VBGeneric-8264807-0
CAT-QuickHealTrojan.Multi
McAfeeArtemis!B556526E3DA7
CylanceUnsafe
K7GWBackdoor ( 00557edb1 )
Cybereasonmalicious.e3da71
BaiduWin32.Trojan.Generic.f
CyrenW32/VB.SF.gen!Eldorado
SymantecInfostealer
ESET-NOD32multiple detections
APEXMalicious
AvastFileRepMalware
CynetMalicious (score: 99)
KasperskyUDS:Trojan-PSW.Win32.Azorult
BitDefenderGen:Variant.Razy.698093
NANO-AntivirusTrojan.Win32.Razy.hlkpnp
MicroWorld-eScanGen:Variant.Razy.698093
TencentMalware.Win32.Gencirc.10cdd799
Ad-AwareGen:Variant.Razy.698093
SophosGeneric Reputation PUA (PUA)
BitDefenderThetaGen:NN.ZexaF.34142.mmGfaWtJITDi
McAfee-GW-EditionBehavesLike.Win32.FilePatcher.cc
FireEyeGeneric.mg.b556526e3da710a1
EmsisoftGen:Variant.Razy.698093 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Multi.dd
AviraHEUR/AGEN.1134710
Antiy-AVLTrojan/Generic.ASMalwS.10558C2
MicrosoftRansom:Win32/Locky.SA!MTB
GDataGen:Variant.Razy.698093
VBA32Trojan.Wacatac
MAXmalware (ai score=89)
RisingTrojan.Injector!1.C6AF (CLASSIC)
YandexTrojan.Injector!ixI/YyhZD1g
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.ENLK!tr
AVGFileRepMalware

How to remove Razy.698093 (B)?

Razy.698093 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment