Malware

Razy.767020 malicious file

Malware Removal

The Razy.767020 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.767020 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Razy.767020?


File Info:

name: 2EBE2AFC553D47F39D86.mlw
path: /opt/CAPEv2/storage/binaries/a2a7bc07dd60502bfabc2eebcb0485f233dabeb5a0a26ab77a1277482cff2c93
crc32: 3F29B129
md5: 2ebe2afc553d47f39d8621385fb04810
sha1: 37ea2cabb12d2b290ebc4b4fa6cbebddab16140d
sha256: a2a7bc07dd60502bfabc2eebcb0485f233dabeb5a0a26ab77a1277482cff2c93
sha512: 16178bd89eb6a4508ff7570a8a85ebb990938fc6a1ec53db795df21fa68ec41d10ac48f472734af48e145a2f29a5f61b61bda305d7e5b3737eb4f8f8fcb002bd
ssdeep: 3072:7vDdf0/wCfPAxVqn6f3zc9NR9yjd34JSm+NLHBvG+ACngM6/Eaxf0JDIzBV8WGaJ:7vDG/fSqn0cnzylccNc+IMeCKzLGFH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C534F11BA7D4D373C2F503327C962D9AF22F3AA09CE1171B47446926ADF2A5ED513A20
sha3_384: e81d0defaa8dd74a9cec03025e4df0e5bef677af0da15ab80a62cb2a90ac76c7edc01b87d435264b6cf76b9447f038a8
ep_bytes: 558bec83c4e8ff75ec68664b7400ff75
timestamp: 2006-02-17 18:43:00

Version Info:

Comments:
CompanyName: Avira GmbH
FileDescription: Antivirus Control Center
FileVersion: 8.00.70.08
InternalName: Control Center
LegalCopyright: Copyright © 2008 Avira GmbH. All rights reserved.
LegalTrademarks: AntiVir® is a registered trademark of Avira GmbH, Germany.
OriginalFilename: avcenter.exe
PrivateBuild:
ProductName: AntiVir Workstation
ProductVersion: 8.00.70.08
SpecialBuild:
Translation: 0x0800 0x04b0

Razy.767020 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.SpyEyes.l!c
Elasticmalicious (high confidence)
DrWebBackDoor.Qbot.73
MicroWorld-eScanGen:Variant.Razy.767020
FireEyeGeneric.mg.2ebe2afc553d47f3
McAfeePWS-Spyeye.fa
CylanceUnsafe
VIPREVirTool.Win32.Obfuscator.da!j (v)
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
AlibabaTrojanSpy:Win32/SpyEyes.97475c4f
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.c553d4
BitDefenderThetaGen:NN.ZexaF.34212.om0@aaLtIxhc
VirITTrojan.Win32.SpyEyes.EXI
CyrenW32/S-5f8a72a3!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.UPK
TrendMicro-HouseCallTROJ_SPYEYE.SMEP
Paloaltogeneric.ml
KasperskyTrojan-Spy.Win32.SpyEyes.exi
BitDefenderGen:Variant.Razy.767020
NANO-AntivirusTrojan.Win32.SpyEyes.dbozv
AvastWin32:Zbot-MXB [Trj]
TencentWin32.Trojan-spy.Spyeyes.Hvjy
Ad-AwareGen:Variant.Razy.767020
EmsisoftGen:Variant.Razy.767020 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
ZillyaTrojan.SpyEyes.Win32.2041
TrendMicroTROJ_SPYEYE.SMEP
McAfee-GW-EditionBehavesLike.Win32.Generic.dm
SophosMal/Generic-S + Mal/FakeAV-BW
IkarusTrojan.Win32.Spyeye
GDataGen:Variant.Razy.767020
JiangminTrojanSpy.SpyEyes.otc
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan[Spy]/Win32.SpyEyes
ViRobotTrojan.Win32.A.SpyEyes.235520.B
MicrosoftPWS:Win32/Zbot!ZA
AhnLab-V3Spyware/Win32.Zbot.R2551
Acronissuspicious
ALYacGen:Variant.Razy.767020
MAXmalware (ai score=100)
VBA32Trojan.Zeus.EA.0999
APEXMalicious
RisingSpyware.SpyEyes!8.4AA (CLOUD)
YandexTrojanSpy.SpyEyes!HGtWKlDPbFA
SentinelOneStatic AI – Malicious PE
eGambitGeneric.Malware
WebrootW32.Trojan.Gen
AVGWin32:Zbot-MXB [Trj]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Razy.767020?

Razy.767020 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment