Malware

About “Razy.920754” infection

Malware Removal

The Razy.920754 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.920754 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Checks for the presence of known windows from debuggers and forensic tools
  • The following process appear to have been packed with Themida: vidduivp.exe
  • Network activity detected but not expressed in API logs
  • Attempts to identify installed AV products by installation directory
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

How to determine Razy.920754?


File Info:

crc32: 63E9E1BE
md5: 870eefe8c11fd6a329b35b1ab797ac2e
name: 870EEFE8C11FD6A329B35B1AB797AC2E.mlw
sha1: 33714bd9e730aa0ad3d97b3c1263153fff9dcf93
sha256: 0822897c3336073faf73fa391193ea15f55de51aa36d63433a9e794127c34576
sha512: 707fa0f8434b8c1521d105392d2eb6ff010f76e8cd00c4270ed80e40a698ad79738963bf110777f593c36ebd1808b09db277527c96fb69e73bcb4a8941f58725
ssdeep: 196608:WIKiV6Fvjqyw/pgdqKPu6uLLUrn9L67rn9b8DMYTuG:WIDVLy+3KPu6uLLUL9GVoD7Th
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: cerous
ProductVersion: 1.0.0.0
FileVersion: 1.0.0.0
FileDescription:
Translation: 0x0000 0x04b0

Razy.920754 also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 99)
ALYacGen:Trojan.Heur.D.NMW@dywIN8ji
ZillyaTrojan.Coins.Win32.6659
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (W)
Cybereasonmalicious.8c11fd
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
AvastNSIS:PWSX-gen [Trj]
ClamAVWin.Packed.Filerepmalware-9864117-0
KasperskyHEUR:Trojan-Banker.Win32.ClipBanker.gen
BitDefenderGen:Variant.Razy.920754
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanGen:Variant.Razy.920754
TencentWin32.Trojan-banker.Clipbanker.Dygk
BitDefenderThetaAI:Packer.F66FE0C41E
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
FireEyeGeneric.mg.870eefe8c11fd6a3
EmsisoftGen:Variant.Razy.920754 (B)
AviraHEUR/AGEN.1140896
eGambitUnsafe.AI_Score_75%
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitTrojan.Razy.DE0CB2
ZoneAlarmHEUR:Trojan-PSW.Win32.Coins.gen
GDataWin32.Trojan.BSE.HLJWVB
MAXmalware (ai score=85)
VBA32BScope.Trojan.Scar
MalwarebytesMalware.AI.753280343
RisingTrojan.Generic@ML.100 (RDML:fncLfiddF5SoVSPXDKHE2g)
AVGNSIS:PWSX-gen [Trj]

How to remove Razy.920754?

Razy.920754 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment