Malware

Razy.968891 removal instruction

Malware Removal

The Razy.968891 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.968891 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Razy.968891?


File Info:

name: 4570B8C9690DBC9D62AC.mlw
path: /opt/CAPEv2/storage/binaries/ef2599924697cbc494174136e4a84c0a3eb4d37db82016430acb4b6e297a4b45
crc32: A9865D40
md5: 4570b8c9690dbc9d62ac62a1c59e4490
sha1: 6f4c2330f74d13670d3a46ba8dfee3aaf7f2d3aa
sha256: ef2599924697cbc494174136e4a84c0a3eb4d37db82016430acb4b6e297a4b45
sha512: 10cd37f79810f627254e57a2c3b11c78e914866064970dbc1138f04bc479c1ee184882927c77e53d97289b974f35f0758c4ab41cb28bde1c762c894994727548
ssdeep: 3072:RG0xa4ceHdUM5TSdoDQjlC3514JP0lNU475IJ4wpIfad0Pqrv3SK:RN3aM5+doDQq5E6vqJKi/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1861401847BD4F5EBF4B3D1FE7176A3ABB92DF99511C0142BA6014AE588291F06B0F036
sha3_384: 554571aa473d274d9cd30c15b5bea9af7a6357e79125223c6153bd5a8410f5043b7a38f196e9f99e7c4541eed39e85c5
ep_bytes: 833d4bc44200000f85910000008b1d4b
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Razy.968891 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Agent.lz2Y
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.4570b8c9690dbc9d
CAT-QuickHealTrojanPWS.Zbot.Y
McAfeePWS-Zbot.gen.amz
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.74222
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 7000000f1 )
AlibabaTrojanSpy:Win32/EncPk.686262fb
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.9690db
BitDefenderThetaGen:NN.ZexaF.34212.mGX@ai915Klk
VirITTrojan.Win32.SMSSend.DMX
CyrenW32/DelfInject.AM.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Zbot.YW
BaiduWin32.Virus.Krap.a
ClamAVWin.Spyware.Zbot-68085
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.968891
NANO-AntivirusTrojan.Win32.SmsSend.cbobaq
ViRobotTrojan.Win32.A.Zbot.197633.DQ
MicroWorld-eScanGen:Variant.Razy.968891
APEXMalicious
TencentMalware.Win32.Gencirc.114c332b
Ad-AwareGen:Variant.Razy.968891
SophosMal/Generic-R + Mal/EncPk-AEH
ComodoMalware@#cr7qcgol9fup
DrWebTrojan.SMSSend.2363
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionBehavesLike.Win32.ZBot.ch
EmsisoftGen:Variant.Razy.968891 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Razy.968891
JiangminTrojanDownloader.CodecPack.esd
AviraDR/Delphi.Gen8
MAXmalware (ai score=99)
Antiy-AVLTrojan/Generic.ASMalwS.2FBC5
KingsoftWin32.Troj.Generic_a.a.(kcloud)
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftPWS:Win32/Zbot
AhnLab-V3Spyware/Win32.Zbot.R33893
Acronissuspicious
VBA32Malware-Cryptor.Limpopo
ALYacGen:Variant.Razy.968891
TACHYONTrojan-Spy/W32.ZBot.197633.P
MalwarebytesSpyware.ZeuS
PandaTrj/Pacrypt.D
RisingSpyware.Voltar!1.AF1D (CLOUD)
YandexTrojan.GenAsa!kZZRCzoNoEs
IkarusWorm.Win32.Cridex
MaxSecureTrojan.Malware.4418783.susgen
FortinetW32/Zbot.EQPB!tr
AVGWin32:Susn-AU [Trj]
AvastWin32:Susn-AU [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Razy.968891?

Razy.968891 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment