Malware

Razy.821660 (file analysis)

Malware Removal

The Razy.821660 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.821660 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with NsPack
  • Authenticode signature is invalid
  • CAPE detected the OrcusRAT malware family
  • Attempted to write directly to a physical drive
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Razy.821660?


File Info:

name: 3FAF05A0A429018D8527.mlw
path: /opt/CAPEv2/storage/binaries/1d571c70500e34173c9afca7ef02f85a582b2f7fed53a13781797ced6928083b
crc32: 873CD2DB
md5: 3faf05a0a429018d8527aebfc00e697d
sha1: 0983a4b49d9650ed9cfa96bd0f10ba678b1da919
sha256: 1d571c70500e34173c9afca7ef02f85a582b2f7fed53a13781797ced6928083b
sha512: 8c81e32445349ae0c5ab27b64ba143908f2d6ebfeb6b81c24f4f989c7972ff9a102f8cf8cb661a3fe54181ffaef970e52b7443db145dc1a00dd8f79c2f6939bb
ssdeep: 1536:THFusSx9qYMhdFHS8qdydo3nTzhYxJA+CwNUtBZVY9v8pr7eSefCQcgfd1HsYt:TxS4jHS8q/3nTzePCwNUh4E97aaep
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D8A30227A7F4B558F84747B096725A61CD1AFD247E2ACE4F01B830031EFA1936E4AB53
sha3_384: 4697e49520bd7b99cc7a17555922c548a5e1a5fbe5e776f654855cca2ba5555785e2d2467f3cf6d2dde7547b5874c532
ep_bytes: e8000000008304241c64ff3500000000
timestamp: 2010-07-14 22:04:13

Version Info:

CompanyName: Google Inc.
FileDescription: Google Chrome
FileVersion: 18.0.1025.142
InternalName: chrome_exe
LegalCopyright: Copyright (C) 2006-2010 Google Inc. All Rights Reserved.
OriginalFilename: chrome.exe
ProductName: Google Chrome
ProductVersion: 18.0.1025.142
CompanyShortName: Google
ProductShortName: Chrome
LastChange: 129054
Official Build: 1
Translation: 0x0409 0x04b0

Razy.821660 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.821660
CAT-QuickHealBackdoor.Zegost.C3
McAfeeDropper-FAX!3FAF05A0A429
MalwarebytesCrypt.Trojan.Malicious.DDS
ZillyaTrojan.Generic.Win32.344553
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005257651 )
K7GWTrojan ( 005257651 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Trojan.Kryptik.t
VirITTrojan.Win32.Generic.ABKF
CyrenW32/Downloader.AT.gen!Eldorado
SymantecBackdoor.Trojan
ESET-NOD32a variant of Win32/Kryptik.IBO
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.821660
NANO-AntivirusTrojan.Win32.Bjlog.rdwiy
AvastWin32:Zegost-I [Drp]
TencentTrojan.Win32.Agent.q
EmsisoftGen:Variant.Razy.821660 (B)
F-SecureTrojan.TR/Tiarev.A
DrWebTrojan.DownLoader1.26310
VIPREGen:Variant.Razy.821660
TrendMicroTROJ_KRYPTK.SMUI
McAfee-GW-EditionDropper-FAX!3FAF05A0A429
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.3faf05a0a429018d
SophosMal/PWS-FY
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Razy.821660
JiangminTrojan/PSW.Bjlog.elf
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Tiarev.A
MAXmalware (ai score=88)
Antiy-AVLTrojan[PSW]/Win32.Bjlog
XcitiumBackdoor.Win32.Popwin.~IQ@ogvrk
ArcabitTrojan.Razy.DC899C
ViRobotTrojan.Win32.A.PSW-Bjlog.98064.D
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:Win32/Zegost
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Bjlog.R30980
BitDefenderThetaGen:NN.ZexaF.36318.fm1@amCiYFfj
ALYacGen:Variant.Razy.821660
TACHYONTrojan-PWS/W32.Bjlog.98064.D
VBA32SScope.Adware.Baidu.01015
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_KRYPTK.SMUI
RisingTrojan.Kryptik!1.ADBE (CLASSIC)
YandexTrojan.Agent!x9hFJdSpYYs
IkarusTrojan-Dropper.Win32.Swisyn
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Genome.AFT!tr
AVGWin32:Zegost-I [Drp]
Cybereasonmalicious.0a4290
DeepInstinctMALICIOUS

How to remove Razy.821660?

Razy.821660 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment