Malware

Razy.698093 removal guide

Malware Removal

The Razy.698093 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.698093 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (7 unique times)
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Checks for the presence of known windows from debuggers and forensic tools
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Detects VirtualBox through the presence of a registry key
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system

Related domains:

bit.do
rebrand.ly
jamshed.pk
backgrounds.pk
karimgousa.ug
telete.in
karimgouss.ug
hsagoi.ac.ug
gordons.ac.ug
apps.identrust.com

How to determine Razy.698093?


File Info:

crc32: 04BC5B30
md5: 9ecf4d06241c3f09c06ca879261d43fa
name: 9ECF4D06241C3F09C06CA879261D43FA.mlw
sha1: 961267a60529e5fa8cf5186386563afc634ef615
sha256: 1eb39c14abcac667ca35cf294bfda8ac6282b93028d830f1665afa2a87cff4ef
sha512: 2e6b863ed9f4d75c8d87f52f84ff4f6814a7eb9852d6d9c5daffb0202757d01eeb96ab25c71fd87e9e988fd8a3a803e7188919c23161ff70b8a713d7b92258f6
ssdeep: 12288:Qi1nQBuPot+7pyxKmAoFFK7ehFmGh7q+5RoS:Q6Qrt+7KU7evmGU+5
type: PE32 executable (console) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Razy.698093 also known as:

BkavW32.AIDetectVM.malware2
K7AntiVirusBackdoor ( 00557edb1 )
LionicTrojan.Win32.Chapak.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen9.55566
CynetMalicious (score: 85)
CAT-QuickHealTrojan.Chapak
ALYacGen:Variant.Razy.698093
CylanceUnsafe
ZillyaTrojan.Injector.Win32.748549
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Chapak.01428354
K7GWBackdoor ( 00557edb1 )
Cybereasonmalicious.6241c3
TrendMicroRansom_Locky.R002C0DG320
SymantecInfostealer
ESET-NOD32a variant of Win32/Injector.EMLN
APEXMalicious
AvastWin32:DropperX-gen [Drp]
ClamAVWin.Trojan.VBGeneric-8264807-0
KasperskyTrojan.Win32.Chapak.eohx
BitDefenderGen:Variant.Razy.698093
NANO-AntivirusTrojan.Win32.Razy.hlkpnp
MicroWorld-eScanGen:Variant.Razy.698093
TencentMalware.Win32.Gencirc.10cdd799
Ad-AwareGen:Variant.Razy.698093
SophosMal/Generic-S
ComodoMalware@#2i67ay9gxseq
F-SecureHeuristic.HEUR/AGEN.1134710
BitDefenderThetaGen:NN.ZevbaF.34186.in3@aydw5WBi
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
FireEyeGeneric.mg.9ecf4d06241c3f09
EmsisoftGen:Variant.Razy.698093 (B)
SentinelOneDFI – Suspicious PE
JiangminTrojan.Multi.dd
WebrootW32.Trojan.VBGen
AviraHEUR/AGEN.1134710
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/BAT.KillWin
MicrosoftRansom:Win32/Locky.SA!MTB
ArcabitTrojan.Razy.DAA6ED
ZoneAlarmTrojan.Win32.Chapak.eohx
GDataGen:Variant.Razy.698093
McAfeeArtemis!9ECF4D06241C
MAXmalware (ai score=88)
VBA32TrojanBanker.Qhost
TrendMicro-HouseCallRansom_Locky.R002C0DG320
RisingTrojan.Injector!1.C6AF (CLASSIC)
YandexTrojan.Injector!ixI/YyhZD1g
Ikarusnot-a-virus:RiskTool.Win32.Patcher
FortinetW32/Injector.EMPE!tr
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.75d

How to remove Razy.698093?

Razy.698093 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment