Malware

How to remove “Razy.981301”?

Malware Removal

The Razy.981301 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.981301 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • CAPE detected the Alfonoso malware family
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests cookies for information gathering
  • Harvests credentials from local FTP client softwares
  • Collects information to fingerprint the system

How to determine Razy.981301?


File Info:

name: 31252A6A6E817BA9C4D3.mlw
path: /opt/CAPEv2/storage/binaries/87e29aa829b4a0dd4e47ac515f7f311a1e2f581cfabf4b0220ae9fbcb3013e4c
crc32: 4B62906E
md5: 31252a6a6e817ba9c4d38f7e771ec5f1
sha1: 29a1625f31c8ea392e52f5b5ac746cf9bff43bbd
sha256: 87e29aa829b4a0dd4e47ac515f7f311a1e2f581cfabf4b0220ae9fbcb3013e4c
sha512: 9c398024495b3b0f9a5bcb1f54cfe84f2ce8dde22607487cd28a220c18d45333279454e074b736b6e3e89e18627558701890f7a4176dc4c15c5b716438e1ff4e
ssdeep: 12288:VokfGiD8pdNn9KCT7tDlWCXJq7C7HbyyU9lbALDa/ecZpiDg:VoCDMNn9KCf1lWCXJWC7vU9lqkk8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11DC4BE0BE6429076E4632430229D8F6699BD76304923A577B3C42D2D5EF01F2AB36F77
sha3_384: e7d5be7f3ab27d7b79c1f0e449d4b9f67ec8283a986825366bfd3044d83f73b24f8b53d41daad3e306ca82c84a097035
ep_bytes: e884040000e974feffff558bec81ec24
timestamp: 2022-04-17 21:02:57

Version Info:

0: [No Data]

Razy.981301 also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanGen:Variant.Razy.981301
FireEyeGeneric.mg.31252a6a6e817ba9
McAfeeGenericRXSQ-WK!31252A6A6E81
CylanceUnsafe
BitDefenderGen:Variant.Razy.981301
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/PSW.Agent.OKX
APEXMalicious
ClamAVWin.Malware.Zusy-9812688-0
KasperskyHEUR:Trojan-PSW.Win32.Shurk.gen
NANO-AntivirusTrojan.Win32.Shurk.joxrlc
AvastWin32:DullStorm-B [Pws]
TencentMalware.Win32.Gencirc.10d03d4d
Ad-AwareGen:Variant.Razy.981301
EmsisoftGen:Variant.Razy.981301 (B)
DrWebTrojan.PWS.Stealer.32969
ZillyaTrojan.Agent.Win32.2766330
McAfee-GW-EditionGenericRXSQ-WK!31252A6A6E81
Trapminesuspicious.low.ml.score
SophosGeneric ML PUA (PUA)
GDataWin32.Trojan-Stealer.Phoenix.B
JiangminTrojan.PSW.Shurk.q
MAXmalware (ai score=86)
ArcabitTrojan.Razy.DEF935
ZoneAlarmHEUR:Trojan-PSW.Win32.Shurk.gen
MicrosoftPWS:MSIL/Phoenix.GG!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Phoenix.C5094321
BitDefenderThetaGen:NN.ZexaF.34742.IuX@aaazVKci
ALYacGen:Variant.Razy.981301
VBA32BScope.Trojan.Wacatac
MalwarebytesGeneric.Trojan.Malicious.DDS
RisingStealer.Agent!8.C2 (TFE:dGZlOgW8OOCOjRVurg)
YandexTrojan.PWS.Agent!uLEZElhspcU
IkarusTrojan-PSW.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.OKX!tr
AVGWin32:DullStorm-B [Pws]
PandaTrj/GdSda.A

How to remove Razy.981301?

Razy.981301 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment