Malware

About “Razy.902974” infection

Malware Removal

The Razy.902974 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.902974 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Creates a copy of itself
  • Harvests cookies for information gathering

How to determine Razy.902974?


File Info:

name: 00AB69F5672C27122281.mlw
path: /opt/CAPEv2/storage/binaries/d45dc9195490f52ff7eb3ddc26bfe2e035d870ebc4573da6a14cb6939a7bf6df
crc32: 01A7C5EC
md5: 00ab69f5672c271222814c4ab6684bf5
sha1: 2f36c2d6565e6133a71690aec7af0bb1496f4775
sha256: d45dc9195490f52ff7eb3ddc26bfe2e035d870ebc4573da6a14cb6939a7bf6df
sha512: fbb55519ed0ba32e9b2253ae46e53e5f0e3c15340b7023185ba142d205ba48e2196eec62ca754dbabe5c3e23a4ecbfa951f70ae5225c4b3cb30bf48c8c0a05a3
ssdeep: 384:bblK3Az3bscy0Nx5M932zmuh9IR04cZRnJI7vR511z:bblSAjbsc9HK9Gdy64e67vL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FE72D1CAEE687EA9C5DA0DBCA2579401F1B804791F99874AFFD02833448F1C0D73932A
sha3_384: 672fd072b232f39772fc1d4aa667da22e079cc203de3fd94a9343b42c84f45b95df94c91b46988423d4e087719fe016b
ep_bytes: 60be007041008dbe00a0feff57eb0b90
timestamp: 2021-11-20 08:13:48

Version Info:

0: [No Data]

Razy.902974 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.902974
FireEyeGeneric.mg.00ab69f5672c2712
CAT-QuickHealTrojan.GenericRI.S25056300
McAfeeGenericRXAA-AA!00AB69F5672C
CylanceUnsafe
ZillyaTrojan.Agent.Win32.2570933
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 005811d21 )
K7GWTrojan-Downloader ( 005811d21 )
Cybereasonmalicious.5672c2
BitDefenderThetaGen:NN.ZexaF.34084.bmHfaapMNkm
CyrenW32/Dridex.EP.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.FTV
ClamAVWin.Trojan.Generic-9907950-0
KasperskyHEUR:Trojan.Win32.Agent.pef
BitDefenderGen:Variant.Razy.902974
NANO-AntivirusTrojan.Win32.Razy.jilqcs
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.10cf8c34
Ad-AwareGen:Variant.Razy.902974
EmsisoftGen:Variant.Razy.902974 (B)
VIPRETrojan.Win32.Agent.xfc (v)
McAfee-GW-EditionBehavesLike.Win32.Generic.lc
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1ETEWJE
JiangminTrojan.Agent.dsck
MaxSecureTrojan.Malware.300983.susgen
AviraTR/Downloader.Gen
MAXmalware (ai score=85)
Antiy-AVLTrojan/Generic.ASBOL.C4EC
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4786956
Acronissuspicious
VBA32BScope.Backdoor.Androm
ALYacGen:Variant.Razy.902974
MalwarebytesMalware.AI.2963452190
APEXMalicious
YandexTrojan.DL.Agent!f+NnmkpDJU4
IkarusTrojan-Downloader
FortinetW32/Agent.FTV!tr.dldr
AVGWin32:Trojan-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Razy.902974?

Razy.902974 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment