Malware

Razy.774860 (file analysis)

Malware Removal

The Razy.774860 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.774860 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Enumerates services, possibly for anti-virtualization
  • Deletes its original binary from disk
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Razy.774860?


File Info:

crc32: EC7F06D2
md5: d672b12a0327054c8a79b2a42120319b
name: upload_file
sha1: 0b93d4fb8911626f3097745f70e56c88239cb080
sha256: 2b9ee1b754609e41e0c417702b33bdeb39d8f1e557ce99854f67498d3fb760bf
sha512: 3b741b5c3b3d31937f340ab0e1c3aaa2753e0e124e6ffed24257e2e45aed1692571089b12ddd8e7ea9187eb6ef061e267a8d2b147e4f49f5b0abca4a4ca661e7
ssdeep: 24576:u//////////////////////////////////////////////////////////////:
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Razy.774860 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.774860
FireEyeGeneric.mg.d672b12a0327054c
CAT-QuickHealTrojanDropper.Agent
McAfeeRansom-Locky!D672B12A0327
CylanceUnsafe
AegisLabTrojan.Win32.Agent.b!c
SangforMalware
K7AntiVirusTrojan ( 0051918c1 )
BitDefenderGen:Variant.Razy.774860
K7GWTrojan ( 0051798f1 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/S-721a11f7!Eldorado
SymantecPacked.Generic.493
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Tofsee-7090196-1
KasperskyHEUR:Trojan-Dropper.Win32.Agent.pef
AlibabaBackdoor:Win32/Tofsee.01114618
NANO-AntivirusTrojan.Win32.Kryptik.fctovw
ViRobotTrojan.Win32.Z.Tofsee.15661568
RisingTrojan.Kryptik!1.AE8C (CLASSIC)
Ad-AwareGen:Variant.Razy.774860
ComodoTrojWare.Win32.Crypt.C@7vajd0
DrWebTrojan.Siggen10.37666
VIPRETrojan.Win32.Generic!BT
InvinceaMal/Generic-R + Mal/Elenoocka-E
McAfee-GW-EditionBehavesLike.Win32.Backdoor.vc
SophosMal/Elenoocka-E
IkarusTrojan-Ransom.Locky
JiangminBackdoor.Poison.auq
AviraHEUR/AGEN.1120889
MAXmalware (ai score=85)
MicrosoftBackdoor:Win32/Tofsee.T
ArcabitTrojan.Razy.DBD2CC
ZoneAlarmHEUR:Trojan-Dropper.Win32.Agent.pef
GDataGen:Variant.Razy.774860
AhnLab-V3Win-Trojan/RansomCrypt.Exp
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34590.@tW@aazL@sg
VBA32Trojan.FakeAV.01657
ESET-NOD32a variant of Win32/Kryptik.FWWT
TencentMalware.Win32.Gencirc.10bac76d
YandexTrojan.GenAsa!PCE9G5WoD6A
SentinelOneDFI – Malicious PE
FortinetW32/Kryptik.GKVH!tr
AVGWin32:Malware-gen
Cybereasonmalicious.a03270
AvastWin32:Malware-gen
Qihoo-360Win32/Trojan.Dropper.42f

How to remove Razy.774860?

Razy.774860 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment