Malware

How to remove “Razy.940197”?

Malware Removal

The Razy.940197 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.940197 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Creates a copy of itself

How to determine Razy.940197?


File Info:

name: A0DC8AE42D2A96472DCD.mlw
path: /opt/CAPEv2/storage/binaries/364d95454cb50afc09751839ae6d8120f73ebc73fc7021e95e9b473af510f80d
crc32: D2F267E4
md5: a0dc8ae42d2a96472dcdac87609656d8
sha1: bdc1cb802234612422c81128e7b10dfa31c5a76c
sha256: 364d95454cb50afc09751839ae6d8120f73ebc73fc7021e95e9b473af510f80d
sha512: 1966135b41175ed4a2dff8ce5a6a094a03cacb83ca6d8ed19c5975436ed455980d5aff9387cd88c41624e4502e5506696ab4ef77415e2f62526eaa3b38c479bc
ssdeep: 3072:7Lk395hYXJJceADx+39dNnZWSrO9GjWQWTooizCVowEgChmZN2rJXzuqna:7Qq3m9+35kSq9k/oizCVuA0XzDa
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19C04022F33D488FBF1B95E3086A7EB65A775F7182240531BAB601F2F6A34143E921563
sha3_384: 89fc341044ac7d1abc6c708736ae78ddb3374ab9342462c753a0eca15e876958af1b870b1e8e8bc0f2b71b76d11fecfa
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:41

Version Info:

CompanyName: DIGI MICROSERVICE LIMITED COMPANY
FileDescription: AccelPCPro Installer
FileVersion: 1.0.4.55
LegalCopyright: 2018-2019 (Copyright) DIGI MICROSERVICE LIMITED COMPANY
ProductName: AccelPCPro Installer
ProductVersion: 1.0.4.55
Publisher: DIGI MICROSERVICE LIMITED COMPANY
Translation: 0x0000 0x04e4

Razy.940197 also known as:

LionicHacktool.Win32.PCAccelerator.3!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Nemesis.942
FireEyeGen:Variant.Nemesis.942
ALYacGen:Variant.Razy.940197
CylanceUnsafe
SangforRiskware.Win32.Wacapew.C
K7AntiVirusAdware ( 005577f11 )
AlibabaRiskWare:Win32/PCAccelerator.ab7eef61
K7GWAdware ( 005577f11 )
Cybereasonmalicious.42d2a9
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.PCAcceleratePro.I
APEXMalicious
AvastWin32:Adware-gen [Adw]
KasperskyHEUR:Hoax.Win32.PCAccelerator.gen
BitDefenderGen:Variant.Nemesis.942
NANO-AntivirusRiskware.Win32.PCAcceleratePro.iqvrft
TencentWin32.Trojan-psw.Pcaccelerator.Lmkq
SophosGeneric PUA LN (PUA)
TrendMicroTROJ_GEN.R03FC0PKS21
McAfee-GW-EditionPUP-XJI-WM
EmsisoftGen:Variant.Nemesis.942 (B)
Paloaltogeneric.ml
GDataGen:Variant.Razy.940197
AviraHEUR/AGEN.1122005
Antiy-AVLTrojan/Generic.ASMalwS.2C54143
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftProgram:Win32/Wacapew.C!ml
McAfeeArtemis!A0DC8AE42D2A
MAXmalware (ai score=80)
VBA32Adware.Downware
MalwarebytesPUP.Optional.PCAcceleratePro
TrendMicro-HouseCallTROJ_GEN.R03FC0PKS21
RisingMalware.Ymacco!8.11C01 (RDMK:cmRtazpJX/Va2+VgGxNxIrfRx3W/)
YandexTrojan.GenAsa!6dY3TStTfrU
FortinetAdware/PCAcceleratePro
AVGWin32:Adware-gen [Adw]
PandaTrj/CI.A

How to remove Razy.940197?

Razy.940197 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment