Malware

Razy.448584 removal tips

Malware Removal

The Razy.448584 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.448584 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Creates a copy of itself
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Razy.448584?


File Info:

name: 5357A5B7AF53F8F9B985.mlw
path: /opt/CAPEv2/storage/binaries/78a7666c5563ecd88da58930c8e584bc85f270f6a7b989e5de0e2de0a18cf89e
crc32: FD0ABA32
md5: 5357a5b7af53f8f9b98536f503a1f72a
sha1: 65fba539f937641dc34ca8dadadaa9550c8f9fdb
sha256: 78a7666c5563ecd88da58930c8e584bc85f270f6a7b989e5de0e2de0a18cf89e
sha512: 3b8d9bfcfaee077766af126ffc908d06e4d1e66b0fa74c0e019a5d1db047d11cf3695b40f1b0647b60271807b779e35b89e2caa50fe99e662e3b67c051456773
ssdeep: 1536:sdQXoy+So9/Vd0i6AZbB6BHkDwMOD6eQX8HtX9uGcOFj6HA1:Qd0zANDwMG6eQX8H96OFj6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B8C3803A2EFD6237D1A8C2F99FD58426F418E07231126C36A6C387599763D4375D223E
sha3_384: d1c140db51bc6bb3da360b3ec68e426e5aac9a2baf9bf691703961658a47f3c5f7daedd0c3c074bfcd6da275f20c0b87
ep_bytes: 68b8174000e8f0ffffff000000000000
timestamp: 2009-12-28 12:56:44

Version Info:

Translation: 0x0409 0x04b0
Comments: ATF-Cleaner is Freeware and is provided for personal use. Please contact us at licensing@atribune.org for information on licensing ATF-Cleaner for use within your company.
CompanyName: Atribune.org
FileDescription: ATF Cleaner.exe
LegalCopyright: © 2005 Atribune.org
ProductName: ATF Cleaner
FileVersion: 3.00.0002
ProductVersion: 3.00.0002
InternalName: ATF-Cleaner
OriginalFilename: ATF-Cleaner.exe

Razy.448584 also known as:

BkavW32.AIDetectMalware
CynetMalicious (score: 100)
FireEyeGeneric.mg.5357a5b7af53f8f9
CAT-QuickHealTrojan.Vbinjectdp
MalwarebytesBackdoor.IRCBot
VIPREGen:Variant.Razy.448584
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( 0011ef311 )
K7GWTrojan ( 0011ef311 )
Cybereasonmalicious.7af53f
VirITTrojan.Win32.Agent.AJL
CyrenW32/Trojan.BICZ-0516
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.ANF
TrendMicro-HouseCallTROJ_CRYPTOVB.E
ClamAVWin.Trojan.Cryptovb-7789632-0
KasperskyTrojan.Win32.CryptoVB.cc
BitDefenderGen:Variant.Razy.448584
NANO-AntivirusTrojan.Win32.CryptoVB.edguov
MicroWorld-eScanGen:Variant.Razy.448584
AvastWin32:Dropper-gen [Drp]
SophosMal/Nyrate-B
F-SecureTrojan.TR/Patched.Ren.Gen
DrWebDDoS.5651
ZillyaTrojan.CryptoVB.Win32.20
TrendMicroTROJ_CRYPTOVB.E
McAfee-GW-EditionBehavesLike.Win32.VBObfus.ct
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Razy.448584 (B)
IkarusTrojan.Win32.CryptoVB
GDataGen:Variant.Razy.448584
JiangminTrojan/CryptoVB.gs
WebrootW32.Malware.Gen
AviraTR/Patched.Ren.Gen
MAXmalware (ai score=87)
Antiy-AVLTrojan/Win32.CryptoVB
ArcabitTrojan.Razy.D6D848
ViRobotTrojan.Win32.CryptoVB.110592
ZoneAlarmTrojan.Win32.CryptoVB.cc
MicrosoftVirTool:Win32/VBInject.gen!DP
GoogleDetected
AhnLab-V3Worm/Win32.VBNA.C2960
BitDefenderThetaGen:NN.ZevbaF.36662.hm1@ayNADddi
VBA32BScope.Trojan.Buzus
Cylanceunsafe
PandaGeneric Malware
APEXMalicious
RisingMalware.Undefined!8.C (TFE:3:2F3mfrVC4yO)
SentinelOneStatic AI – Malicious PE
FortinetW32/VBInjector.W!tr
AVGWin32:Dropper-gen [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Razy.448584?

Razy.448584 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment