Malware

Razy.727373 removal instruction

Malware Removal

The Razy.727373 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.727373 virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (5 unique times)
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Steals private information from local Internet browsers
  • Attempts to access Bitcoin/ALTCoin wallets
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

telete.in
apps.identrust.com

How to determine Razy.727373?


File Info:

crc32: 0654D89C
md5: e968a672e57fbe015ba793052f1ff688
name: wusa.exe
sha1: 87646b125f9e94c2d0dc0664d37de0cafcf77053
sha256: 08fa587a45fa0c033ed2a5a830c9436ceb0b6b4e59e6bc95d6aaa4d96fb79c37
sha512: f68681da221091a32e8d4e699e717299c2afe29ba7e7ad9fbcc1e2b0f458a7a6bc5903ad8e88090027c5b3e7a489b76eee44637b6d2fa80bbd4701bd6ff54b0a
ssdeep: 12288:y5NLxPf4coMo2Ezwvt04F7dChzLEJtvUtgjT0ROxczbJ+5PZylsvJ5f:INdPfttolzat0M7dJMQmkcx+5PZ55f
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2009-11, 2015 Dave Brotherstone
InternalName: gpup
FileVersion: 1.3.5.0
Comments: A generic(ish) plugin ipdater, built initially for Notepad++
ProductName: gpup
ProductVersion: 1.3.5.0
FileDescription: gpup
OriginalFilename: gpup.exe
Translation: 0x0809 0x04b0

Razy.727373 also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanGen:Variant.Razy.727373
FireEyeGeneric.mg.e968a672e57fbe01
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 005652be1 )
BitDefenderGen:Variant.Razy.727373
K7GWTrojan ( 005652be1 )
Cybereasonmalicious.25f9e9
SymantecTrojan!im
APEXMalicious
GDataWin32.Trojan-Stealer.Raccoon.3AVERH
KasperskyUDS:DangerousObject.Multi.Generic
Endgamemalicious (high confidence)
SophosMal/EncPk-APV
Invinceaheuristic
EmsisoftGen:Variant.Razy.727373 (B)
SentinelOneDFI – Suspicious PE
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Wacatac.C!ml
ArcabitTrojan.Razy.DB194D
ZoneAlarmUDS:DangerousObject.Multi.Generic
CynetMalicious (score: 100)
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34144.1u1@amm91tli
MAXmalware (ai score=81)
VBA32BScope.Trojan.Inject
MalwarebytesTrojan.MalPack
ESET-NOD32a variant of Win32/Kryptik.DYTB
RisingTrojan.GenKryptik!8.AA55 (TFE:dGZlOgFcjFC7SOyXqQ)
FortinetW32/GenKryptik.EOOB!tr
Ad-AwareGen:Variant.Razy.727373
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM20.1.F3EC.Malware.Gen

How to remove Razy.727373?

Razy.727373 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment