Malware

What is “Razy.465099”?

Malware Removal

The Razy.465099 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.465099 virus can do?

  • At least one process apparently crashed during execution
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Unconventionial language used in binary resources: Serbian (Cyrillic)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Razy.465099?


File Info:

name: BBB30083B96CD0133196.mlw
path: /opt/CAPEv2/storage/binaries/59865719b7434e683d2fa2cd030073e74f23b7780582f218c0751a14d242716b
crc32: D0022D31
md5: bbb30083b96cd0133196c3a7aef596e3
sha1: f2ae007994b83d40a60322555087ed4970cdfb0d
sha256: 59865719b7434e683d2fa2cd030073e74f23b7780582f218c0751a14d242716b
sha512: d5f8f6652b932581d0ee5446283c506998c6c85ae857b1dbb00d58c565bd702af9265bb063bf64bfdb4b639ab1a9c7695509f682b60eb60af7d53e041fad1016
ssdeep: 49152:Y3MpfZfpWZNU5XstFviQJXZNhAj/WjntIVKLI7kxHKMPN//4JXTgRItETQSi:Y3YfZxWCSxHmJXT7Z
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T129E55A02A3FA5124F2FB2B70A87856690D7A7E526F39C5DF83442D5C0D706A0E9B1B37
sha3_384: 3eb80c03622192def57f32a01d111f172bbfe26e735bd747ce4b7a9fca9b4b9d9034752bf442b2d4befb5bd89c05f105
ep_bytes: e814080000e98efeffffa16cab410053
timestamp: 2018-09-24 12:15:51

Version Info:

LegalCopyright: Copyright Opera Software 2018
InternalName: Opera
FileVersion: 56.0.3051.31
CompanyName: Opera Software
ProductName: Opera Installer
ProductVersion: 56.0.3051.31
FileDescription: Opera Installer
Translation: 0x0409 0x04b0

Razy.465099 also known as:

MicroWorld-eScanGen:Variant.Razy.465099
FireEyeGeneric.mg.bbb30083b96cd013
ALYacGen:Variant.Razy.465099
CylanceUnsafe
VIPREGen:Variant.Razy.465099
Cybereasonmalicious.3b96cd
Elasticmalicious (moderate confidence)
BitDefenderGen:Variant.Razy.465099
Ad-AwareGen:Variant.Razy.465099
EmsisoftGen:Variant.Razy.465099 (B)
Trapminesuspicious.low.ml.score
SophosGeneric ML PUA (PUA)
GDataGen:Variant.Razy.465099
ArcabitTrojan.Razy.D718CB
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4750521
MAXmalware (ai score=88)
MalwarebytesMalware.Heuristic.1006
APEXMalicious
RisingTrojan.Generic@AI.100 (RDML:vfjBz6lHZUKEi3XuSqb5ig)

How to remove Razy.465099?

Razy.465099 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment