Malware

Should I remove “Razy.862401 (B)”?

Malware Removal

The Razy.862401 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.862401 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Created a service that was not started
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

wpad.local-net
crl.sectigo.com
dcjm.yaomeil.com
www.baidu.com

How to determine Razy.862401 (B)?


File Info:

name: 2A9E1BF17D5D79E8ED6B.mlw
path: /opt/CAPEv2/storage/binaries/b1b0c0338d15c5eda0246cbd8497e52ae69e7fb8ad9a785c5b94c8c96b706ab1
crc32: 8BDE70B1
md5: 2a9e1bf17d5d79e8ed6b5fefdb9ad797
sha1: a825ce797e835f946c0a7158dc62f4da27e96abf
sha256: b1b0c0338d15c5eda0246cbd8497e52ae69e7fb8ad9a785c5b94c8c96b706ab1
sha512: ab8619b665a697156a9561ae5fee0de879d60d264e5e9300cf96777a2c05ea5537bff412944e7b7d6fe8cf3c7be96ad5e321bd9cb9ce03cc371ce1a51d9c265f
ssdeep: 196608:0RnvORtjEbnfArO2e8Jz6999Oj5ZEqHZUtISEYZpsxIH5u0fKph8wkfrU8anAmpI:0Rn2wDWxeqzU9+Zk0qDH7U8PfrU1ARoQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D5A63366100225B8F6A23C74A32DFCE069867C230F5534755C47DAEA4936EC3E7DAB0B
sha3_384: 95c7869cd3cb5a846ba633f3b04400d327776f39ed52dda6ec4cf55829608c58ae3d489c584d000d3222675afbad0a32
ep_bytes: 60be003058008dbe00e0e7ffc78768ff
timestamp: 2021-09-22 07:36:33

Version Info:

CompanyName: Simple Notepad
FileDescription: Simple Notepad setup Wizard
FileVersion: 11.0.0.10
InternalName: setup.exe
LegalCopyright: Copyright (c) Simple Notepad
OriginalFilename: setup.exe
ProductName: Simple Notepad
ProductVersion: 11.0.0.10
Translation: 0x0804 0x03a8

Razy.862401 (B) also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Siggen12.31083
MicroWorld-eScanGen:Variant.Razy.862401
FireEyeGeneric.mg.2a9e1bf17d5d79e8
CAT-QuickHealTrojan.GenericRI.S23535535
McAfeeGenericRXAA-AA!2A9E1BF17D5D
CylanceUnsafe
ZillyaTool.YouXun.Win32.1419
SangforInfostealer.Win32.Convagent.gen
AlibabaAdWare:Win32/YouXun.102d
K7GWRiskware ( 0058a9391 )
K7AntiVirusRiskware ( 0058a9391 )
CyrenW32/YouXun.D.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/RiskWare.YouXun.AF
Paloaltogeneric.ml
KasperskyVHO:Trojan-Banker.Win32.Convagent.gen
BitDefenderGen:Variant.Razy.862401
AvastWin32:AdwareX-gen [Adw]
Ad-AwareGen:Variant.Razy.862401
SophosMal/Generic-S (PUA)
TrendMicroTROJ_GEN.R002C0WKM21
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
EmsisoftGen:Variant.Razy.862401 (B)
IkarusPUA.RiskWare.Youxun
GDataGen:Variant.Razy.862401
JiangminTrojanDropper.Dorgam.wj
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASMalwS.34D11F7
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Adware/Win.Generic.R451085
VBA32BScope.Trojan.FakeAlert
ALYacGen:Variant.Razy.862401
MalwarebytesPUP.Optional.ChinAd
TrendMicro-HouseCallTROJ_GEN.R002C0WKM21
RisingAdware.LinkAdd!1.CD70 (CLASSIC)
YandexPUA.Downloader!ioq4OsZClL0
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_90%
FortinetRiskware/YouXun
AVGWin32:AdwareX-gen [Adw]
MaxSecureTrojan.Malware.74650932.susgen

How to remove Razy.862401 (B)?

Razy.862401 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment