What is “Razy.465099 (B)”?

Malware Removal

The Razy.465099 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware - Review 2020

GridinSoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend to use GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the TRIAL period.
6-day free trial available.

What Razy.465099 (B) virus can do?

  • At least one process apparently crashed during execution
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Unconventionial language used in binary resources: Serbian (Cyrillic)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Razy.465099 (B)?

File Info:

name: 16F114588C070B07935B.mlw
path: /opt/CAPEv2/storage/binaries/dac3689efbde32da380dc3d555d2be052a333b8a6361a52cec9c5946a12e779c
crc32: B3BE2336
md5: 16f114588c070b07935b7f3923cddd68
sha1: efef4012c06c2d9a49a20e1caeb6291082b6d1cd
sha256: dac3689efbde32da380dc3d555d2be052a333b8a6361a52cec9c5946a12e779c
sha512: bef5faeb04519f12b67acfbd16e384580c763db35910672e1c03cbfebf0c1bcd7ac47227ff81d67e3d81747b25a75dafb772fd8f2a2a6f5cf7d413df2139c188
ssdeep: 49152:w3ffZHHLob7+8w5hC804HjGWIYVJLFydD1t7UopRnuF9YcN7v1EzIVsSWOmutOgN:w3ffZstBmCeTWOD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19A064902B2FA5124F2FB2B70EC3C57290A767E465FB9C59FA34428D81D705A0B970B67
sha3_384: 204ee9f06d174fae68346a51ad563938427ca703403cad38e94d582ee966014cb639bfdd6ba8572f5f1441a388b26521
ep_bytes: e814080000e98efeffffa16cab410053
timestamp: 2019-01-28 05:00:00

Version Info:

LegalCopyright: Copyright Opera Software 2019
InternalName: Opera
FileVersion: 58.0.3135.53
CompanyName: Opera Software
ProductName: Opera Installer
ProductVersion: 58.0.3135.53
FileDescription: Opera Installer
Translation: 0x0409 0x04b0

Razy.465099 (B) also known as:

SophosGeneric ML PUA (PUA)
EmsisoftGen:Variant.Razy.465099 (B)
MAXmalware (ai score=87)
CynetMalicious (score: 100)
RisingTrojan.Generic@AI.100 (RDML:535OV/RJl9VC0UuiouNvsQ)

How to remove Razy.465099 (B)?

Razy.465099 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment