Malware

Razy.792177 (B) (file analysis)

Malware Removal

The Razy.792177 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.792177 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Razy.792177 (B)?


File Info:

name: 2C0BF4A2CEC50C546039.mlw
path: /opt/CAPEv2/storage/binaries/dfac342ae50e1a997568e41cac080ed211bb34c03ffd2281b62ef63588a40b3a
crc32: 8E198F9B
md5: 2c0bf4a2cec50c54603993282b4b0f7a
sha1: 9d8cd51d0e40586d7cf4835f4e12b4c93775d2f5
sha256: dfac342ae50e1a997568e41cac080ed211bb34c03ffd2281b62ef63588a40b3a
sha512: 4704eaab295041797f1e256d04393aa8ea9660b5ba9c2cca2c8953b298752c1a5a9332cacbc0390540501fc0b29b9db10cff81c3592984937ce2afb89d48aeb6
ssdeep: 768:GG3w1MjbWdgZU0RV/Eu9C9D2T/sXJpyvvRGvFL05VRJWYhbGYNmyxQfE7r:bAK/Eg7V/tYsadOXWE2sn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D143F1158DD18A92F60F0B7821DA6A7AF710D4006BAA13CB2BF6747CAD63FD04D78139
sha3_384: e511923d1af2a5b3204dcccf2abb1faf984fa4adb540d929850aeb5fb83b92572492132c551ceac7605b7287b7cfef01
ep_bytes: 60be005041008dbe00c0feff5783cdff
timestamp: 2002-08-07 19:35:04

Version Info:

0: [No Data]

Razy.792177 (B) also known as:

BkavW32.AIDetectMalware
LionicRiskware.Win32.Generic.l0jn
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Razy.792177
ClamAVWin.Trojan.Dialer-202
FireEyeGeneric.mg.2c0bf4a2cec50c54
CAT-QuickHealDialer.Porndialer.29872
McAfeeArtemis!2C0BF4A2CEC5
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Razy.792177
SangforTrojan.Win32.Save.a
K7AntiVirusDialer ( 0055e3fa1 )
AlibabaRiskWare:Win32/eConnect.4ea78e2c
K7GWDialer ( 0055e3fa1 )
Cybereasonmalicious.2cec50
CyrenW32/Webdialer.gen!GSA
SymantecDialer.Generic
ESET-NOD32a variant of Win32/Dialer.0190-Dialers
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:Porn-Dialer.Win32.eConnect
BitDefenderGen:Variant.Razy.792177
NANO-AntivirusTrojan.Win32.Online.cxhiaz
SUPERAntiSpywarePUP.Porndialer/Variant
AvastWin32:Dialer-ACP [Trj]
SophosDial/190-A
F-SecureDialer.DIAL/000283
DrWebDialer.Online.10
ZillyaDialer.eConnect.Win32.5
TrendMicroDIAL_RAS.HE
McAfee-GW-EditionBehavesLike.Win32.Dialer.qc
EmsisoftGen:Variant.Razy.792177 (B)
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Razy.792177
JiangminPorn-Dialer.eConnect.g
WebrootW32.Malware.gen
AviraDIAL/000283
Antiy-AVLGrayWare[Porn-Dialer]/Win32.eConnect
XcitiumApplicUnwnt.Win32.PornDialer.0190-Dialers._0@1dgmqr
ArcabitTrojan.Razy.DC1671
ZoneAlarmnot-a-virus:Porn-Dialer.Win32.eConnect
MicrosoftTrojan:Win32/Vindor!pz
GoogleDetected
AhnLab-V3Adware/Win32.Dialer.R21773
BitDefenderThetaGen:NN.ZexaF.36350.dmGfaSlDXGA
ALYacGen:Variant.Razy.792177
MAXmalware (ai score=100)
VBA32BScope.Dialer.Premium
Cylanceunsafe
PandaDialer.Gen
TrendMicro-HouseCallDIAL_RAS.HE
RisingTrojan.Dialer-0190-Dialers!8.151B (TFE:5:iyrrO65PUrS)
YandexTrojan.GenAsa!yC+QEnz/pyU
Ikarusnot-a-virus:Porn-Dialer.Win32.Rdial
MaxSecureTrojan.Malware.73498094.susgen
FortinetW32/Scar.FMKE!tr
AVGWin32:Dialer-ACP [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_60% (D)

How to remove Razy.792177 (B)?

Razy.792177 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment