Malware

Razy.892117 (file analysis)

Malware Removal

The Razy.892117 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.892117 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Razy.892117?


File Info:

name: 2E985F810A3A1BD2AA0B.mlw
path: /opt/CAPEv2/storage/binaries/45b4fb946a97d779bf2573f3d4c440ed67260f62a0e1c9eb819a71e839a292e1
crc32: 38945FAA
md5: 2e985f810a3a1bd2aa0bbc745869833f
sha1: 6d68fcbaa0f606b96aef07f6b99b9f391f9da291
sha256: 45b4fb946a97d779bf2573f3d4c440ed67260f62a0e1c9eb819a71e839a292e1
sha512: 4d8c2db6e5caeeca8b4711c5b10cee1fefe9c757f41504248791b3260efe31730134987f5bbcfb3b25952fa52b8b352d93e5bb80c758e834b53a1a6b7102b38e
ssdeep: 768:aARO/CCrUchkFPzGEwIKG2OBcs1ddO9Z/6Q6+RkDfo3E6aHAYmC/wuEgw7:aiO/jrUchV1R+foPagYu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1763318636961C8B1F16945B512B60738F830EA6100FA975BEFC0DEB02DBBB36DB5940D
sha3_384: 4825f5a0cbcf80f64c96c5c49c0d9623880bf337dcf14011103317dcc56d774f742ecb111ff877fb50482108c2c607fa
ep_bytes: e87b490000e81249000033c0c3909090
timestamp: 2021-06-04 03:50:22

Version Info:

0: [No Data]

Razy.892117 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.892117
ClamAVWin.Malware.Amhfbqa-9876798-0
FireEyeGeneric.mg.2e985f810a3a1bd2
McAfeeGenericRXPT-GW!2E985F810A3A
CylanceUnsafe
VIPREGen:Variant.Razy.892117
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/Agent.ENH.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.GHY
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Trojan.Win32.Agent.gen
BitDefenderGen:Variant.Razy.892117
NANO-AntivirusTrojan.Win32.Razy.iwlbdv
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Agentb.wp
Ad-AwareGen:Variant.Razy.892117
TACHYONTrojan/W32.Agent.52736.AQP
SophosML/PE-A
ComodoPacked.Win32.MUPX.Gen@24tbus
ZillyaTrojan.Agent.Win32.2779864
McAfee-GW-EditionBehavesLike.Win32.RAHack.qm
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Razy.892117 (B)
IkarusTrojan-Downloader
GDataWin32.Trojan.PSE.1ETEWJE
JiangminTrojan.Agent.dilb
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASBOL.C4EC
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C4548399
ALYacGen:Variant.Razy.892117
MAXmalware (ai score=89)
RisingDownloader.Agent!1.DEFD (CLASSIC)
YandexTrojan.Agent!lZfgwuN6QHM
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.FTV!tr.dldr
BitDefenderThetaAI:Packer.FDBFFEF41E
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.10a3a1
PandaTrj/GdSda.A

How to remove Razy.892117?

Razy.892117 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment