Categories: Malware

Razy.967478 (file analysis)

The Razy.967478 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.967478 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Executed a command line with /V argument which modifies variable behaviour and whitespace allowing for increased obfuscation options
  • Disables host Start Menu search
  • Removes Networking icon from Start menu, Taskbar and notifications
  • Removes Start menu and Taskbar pinned programs
  • Removes default programs, folders and network connections from Start menu
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempted to write directly to a physical drive
  • Disables AppV (process) virtualization
  • Disables backups, often seen in ransomware
  • Disables host Context Menu in Taskbar and Start
  • Disables host Power options (shutdown, logoff, lock, change password)
  • Disables ability to restore system to default state
  • Attempts to disable or modify the Run command from the Start menu and the New Task (Run) command from Task Manager
  • Attempts to disable Windows Defender
  • Hides Recycle Bin icon
  • Attempts to block SafeBoot use by removing registry keys
  • Uses suspicious command line tools or Windows utilities

How to determine Razy.967478?


File Info:

name: 966BDBCFD32C56377778.mlwpath: /opt/CAPEv2/storage/binaries/a0297bdb13e6f7b167325fe46e193ca908af38155a4e6d3f142e2b3b3e4a58c6crc32: D4D6E37Dmd5: 966bdbcfd32c56377778dba6e47c61casha1: f3f4f00b0b1d4c559999ad4a9266f07b24c6ef7fsha256: a0297bdb13e6f7b167325fe46e193ca908af38155a4e6d3f142e2b3b3e4a58c6sha512: 22ada4facfa513430fe91ede9c457aedd1eeaf96216a9e45ca39528a32a318d6922542bae7b4b10a4d8f967f033794bfda26e3c00a3995e4e38557a8eb17378cssdeep: 768:IBFF5gZz0G9oUOsUEA1TaJ0g6kn0ihMBN/bBAqK98Sum:c5gZz0G9omUEGg6kn3KBNFAqKSSdtype: PE32 executable (console) Intel 80386, for MS Windowstlsh: T10B634E1E7A10C303D1502DBD9476677C8F256AB0C6D8C39296A56A1FCAD0CB0673FCB6sha3_384: 1fbb755ea21aa3bf8d67d72c82e026ee13dd706922bd22ad2efc329b0c172c568665689b53d71c53ab0f5bbef5d18bb6ep_bytes: e802040000e974feffff558bec8b4508timestamp: 2021-10-17 11:19:34

Version Info:

0: [No Data]

Razy.967478 also known as:

Lionic Trojan.Win32.Diztakun.4!c
DrWeb Trojan.Siggen15.26490
MicroWorld-eScan Gen:Variant.Razy.967478
McAfee GenericRXQK-UT!966BDBCFD32C
Cylance Unsafe
Sangfor Trojan.Win32.Diztakun.gen
K7AntiVirus Trojan ( 005892f31 )
Alibaba Trojan:Win32/Diztakun.40344c59
K7GW Trojan ( 005892f31 )
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/KillWin.NDE
TrendMicro-HouseCall TROJ_GEN.R011C0WJK21
Paloalto generic.ml
Kaspersky HEUR:Trojan.Win32.Diztakun.gen
BitDefender Gen:Variant.Razy.967478
Avast Win32:MalwareX-gen [Trj]
Rising Trojan.Generic@ML.80 (RDMK:H8hAF6Q7kdPvkdbxlRp9gw)
Ad-Aware Gen:Variant.Razy.967478
Emsisoft Gen:Variant.Razy.967478 (B)
F-Secure Trojan.TR/Diztakun.ytrhx
TrendMicro TROJ_GEN.R011C0WJK21
McAfee-GW-Edition GenericRXQK-UT!966BDBCFD32C
FireEye Gen:Variant.Razy.967478
Sophos Mal/Generic-S
GData Gen:Variant.Razy.967478
Jiangmin Trojan.Generic.gwtef
Avira TR/Diztakun.ytrhx
MAX malware (ai score=80)
Gridinsoft Ransom.Win32.Wacatac.sa
Arcabit Trojan.Razy.DEC336
Microsoft Trojan:Win32/Wacatac.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Generic.R446286
VBA32 BScope.Trojan.KillProc
ALYac Gen:Variant.Razy.967478
Malwarebytes Generic.Malware/Suspicious
APEX Malicious
Tencent Trojan.Win32.BitCoinMiner.la
Yandex Trojan.Diztakun!VOwusq8eASY
Ikarus Win32.Outbreak
MaxSecure Trojan.Malware.73718646.susgen
Fortinet W32/PossibleThreat
AVG Win32:MalwareX-gen [Trj]
Panda Trj/GdSda.A

How to remove Razy.967478?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

MSIL/GenKryptik.GXIZ information

The MSIL/GenKryptik.GXIZ is considered dangerous by lots of security experts. When this infection is active,…

2 weeks ago

Malware.AI.2789448175 (file analysis)

The Malware.AI.2789448175 is considered dangerous by lots of security experts. When this infection is active,…

2 weeks ago

Jalapeno.1878 removal instruction

The Jalapeno.1878 is considered dangerous by lots of security experts. When this infection is active,…

2 weeks ago

What is “Trojan.Heur3.LPT.YmKfaKBcBekib”?

The Trojan.Heur3.LPT.YmKfaKBcBekib is considered dangerous by lots of security experts. When this infection is active,…

2 weeks ago

How to remove “Worm.Win32.Vobfus.exmt”?

The Worm.Win32.Vobfus.exmt is considered dangerous by lots of security experts. When this infection is active,…

2 weeks ago

About “TrojanDownloader:Win32/Beebone.JO” infection

The TrojanDownloader:Win32/Beebone.JO is considered dangerous by lots of security experts. When this infection is active,…

2 weeks ago