Malware

About “Razy.871950” infection

Malware Removal

The Razy.871950 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.871950 virus can do?

  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Razy.871950?


File Info:

crc32: CA98BF6F
md5: 62e275d1c4b7bd3d17e92e94f44b0410
name: 62E275D1C4B7BD3D17E92E94F44B0410.mlw
sha1: 70f2956933ab7c4a0c8fcf7f5be1a7965b292576
sha256: 5be96ade5a7a048dff79d94ff48887b0f800bd27b7aefdc3d4f2fa1670f64df1
sha512: b7f3debe9c8aba54a450e24eea1e2bd1bbf14eadb54537fe761bdedf4491874567789360af988eaa477069fcfb2a5e6ead8aca45fc83ca1f5c01b1430108dc6b
ssdeep: 768:fTE2/kB8x4vdiabv4zUVvivgX6vqWrd8IGPhOV:f42AZNcUoS6ZreIG5E
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x4f5cx8005x7248x6743x6240x6709 x8bf7x5c0ax91cdx5e76x4f7fx7528x6b63x7248
FileVersion: 14.23.28008.0
Comments: x672cx7a0bx5e8fx4f7fx7528x6613x8bedx8a00x7f16x5199(http://www.eyuyan.com)
ProductName: vcruntime140_1
ProductVersion: 14.23.28008.0
FileDescription: vcruntime140_1
Translation: 0x0804 0x04b0

Razy.871950 also known as:

K7AntiVirusRiskware ( 0040eff71 )
LionicTrojan.Win32.Razy.4!c
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop18.7330
CynetMalicious (score: 99)
ALYacGen:Variant.Razy.871950
CylanceUnsafe
ZillyaTrojan.Bingoml.Win32.5201
SangforTrojan.Win32.Bingoml.cbza
AlibabaTrojan:Win32/Bingoml.9712f448
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.1c4b7b
CyrenW32/Trojan.ZLLR-8211
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Bingoml.cbza
BitDefenderGen:Variant.Razy.871950
MicroWorld-eScanGen:Variant.Razy.871950
TencentWin32.Trojan.Bingoml.Wpti
Ad-AwareGen:Variant.Razy.871950
SophosMal/Generic-S
BitDefenderThetaAI:Packer.261573B11F
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R03FC0PH121
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.qh
FireEyeGen:Variant.Razy.871950
EmsisoftGen:Variant.Razy.871950 (B)
JiangminTrojan.Bingoml.ayu
AviraTR/Redcap.rgiyp
ZoneAlarmTrojan.Win32.Bingoml.cbza
GDataWin32.Application.PUPStudio.A
McAfeeTrojan-FPEY!62E275D1C4B7
MAXmalware (ai score=100)
VBA32BScope.Trojan.Wacatac
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R03FC0PH121
YandexTrojan.Bingoml!hxyGqQgduF0
IkarusTrojan.SuspectCRC
MaxSecureDropper.Dinwod.frindll
FortinetW32/CoinMiner.BBYK!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Razy.871950?

Razy.871950 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment