Malware

Razy.702162 information

Malware Removal

The Razy.702162 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.702162 virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Attempts to delete volume shadow copies
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Uses suspicious command line tools or Windows utilities

How to determine Razy.702162?


File Info:

crc32: 71AF6FC1
md5: edbf07eaca4fff5f2d3f045567a9dc6f
name: EDBF07EACA4FFF5F2D3F045567A9DC6F.mlw
sha1: 9292fa66c917bfa47e8012d302a69bec48e9b98c
sha256: ed0632acb266a4ec3f51dd803c8025bccd654e53c64eb613e203c590897079b3
sha512: 731214358d4fcecdafe0d386a305a130185727b20704e6251e37ac5feb35eff8f3f31d8c740954feb57c699cc5975c3bb50fac5c5202c5933c4fe0dfd06bc8e6
ssdeep: 3072:SLu8kCHp4EYPZE5CIv4Nc4GiM9vAZTponZNLQuHmmYxpwbvANK:38Z2E5biM9MTKnXLQuHmmaQvaK
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 IDM Computer Solutions, Inc. All rights reserved.
InternalName: IDMipdate.exe
FileVersion: 2.0.0.14
CompanyName: IDM Computer Solutions, Inc.
ProductName: IDM ipdate Tool
ProductVersion: 2.0.0.14
FileDescription: IDM ipdate Tool
OriginalFilename: IDMipdate.exe
Translation: 0x0409 0x04b0

Razy.702162 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 005691551 )
LionicHacktool.Win32.Krap.lKMc
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.32017
CynetMalicious (score: 100)
CAT-QuickHealRansom.WSLocker.S15564067
ALYacTrojan.Ransom.Filecoder
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.15036
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/GanWasteCrypt.ea95eca2
K7GWTrojan ( 005691551 )
Cybereasonmalicious.aca4ff
CyrenW32/Ransom.LULL-0120
SymantecRansom.WastedLocker
ESET-NOD32Win32/Filecoder.WastedLocker.A
APEXMalicious
AvastWin32:DangerousSig [Trj]
KasperskyHEUR:Trojan.Win32.Yakes.pef
BitDefenderGen:Variant.Razy.702162
NANO-AntivirusTrojan.Win32.Encoder.hlxnso
ViRobotTrojan.Win32.S.Ransom.974224
MicroWorld-eScanGen:Variant.Razy.702162
TencentWin32.Trojan.Filecoder.Aojn
Ad-AwareGen:Variant.Razy.702162
SophosMal/Generic-S + Troj/Ransom-GAC
ComodoMalware@#2cut97unh73ow
BitDefenderThetaGen:NN.ZexaF.34058.7q1@aOgwOIai
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.WASTEDLOCKER.YAAF-A
McAfee-GW-EditionTrojan-Cobalt
FireEyeGeneric.mg.edbf07eaca4fff5f
EmsisoftGen:Variant.Razy.702162 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.DelShad.zp
WebrootW32.Ransom.Gen
AviraTR/AD.Ursnif.fsmes
Antiy-AVLTrojan/Generic.ASCommon.1BE
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/GanWasteCrypt.SN!MTB
ArcabitTrojan.Razy.DAB6D2
GDataGen:Variant.Razy.702162
TACHYONRansom/W32.WastedLocker.974224
AhnLab-V3Trojan/Win32.Trojanspy.C4141536
Acronissuspicious
McAfeeTrojan-Cobalt
MAXmalware (ai score=100)
VBA32BScope.TrojanDownloader.Dridex
MalwarebytesRansom.BinADS
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.Win32.WASTEDLOCKER.YAAF-A
RisingTrojan.Kryptik!1.C9D2 (CLASSIC)
YandexTrojan.Agent!zU++nzJQGSw
IkarusTrojan-Ransom.WastedLocker
MaxSecureTrojan.Malware.102443773.susgen
FortinetW32/Kryptik.GAC!tr.ransom
AVGWin32:DangerousSig [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/TrojanPSW.Gozi.HxQBL8AA

How to remove Razy.702162?

Razy.702162 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment