Malware

Razy.479098 (B) (file analysis)

Malware Removal

The Razy.479098 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware - Review 2020

GridinSoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend to use GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the TRIAL period.
6-day free trial available.

What Razy.479098 (B) virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking

How to determine Razy.479098 (B)?


File Info:

crc32: A57F87AF
md5: 2089f5f2423a6e00dfe6cf9493bdd0f8
name: 2089F5F2423A6E00DFE6CF9493BDD0F8.mlw
sha1: a98a72ceb55727c2814c1df7e886174016d1214d
sha256: 0db33d053b080713229b75a85226806ca9cca10c204507adbdf1471dd97cc0b7
sha512: 5445b08254899dfd1edd77d5e0f062e8839d1fa4096de00036d7a288cd45246e4798a0008ae8a5b9215219418af204e2f6f57e81c0aaba49893cbc94eac3c122
ssdeep: 384:/uV6/I1rOxSPBiBOtVNthqaBkKD17aHKDwj4sJ8gnxAI6v:WV1EPBCNrqaBhuMsyr
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright @2021 5DD7
InternalName: Loader
FileVersion: 1, 0, 0, 0
CompanyName: 5DD7
Comments: PSCAD Super User
ProductName: PSCAD 5.00 Loader
ProductVersion: 1.0
FileDescription: PSCAD 5.00 Loader
OriginalFilename: Loader
Translation: 0x0409 0x04b0

Razy.479098 (B) also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
McAfeeGenericRXNP-CN!6F3E25043CFE
CylanceUnsafe
Cybereasonmalicious.2423a6
APEXMalicious
AvastWin32:Evo-gen [Susp]
BitDefenderGen:Variant.Razy.479098
MicroWorld-eScanGen:Variant.Razy.479098
Ad-AwareGen:Variant.Razy.479098
McAfee-GW-EditionGenericRXNP-CN!6F3E25043CFE
FireEyeGen:Variant.Razy.479098
EmsisoftGen:Variant.Razy.479098 (B)
MicrosoftProgram:Win32/Wacapew.C!ml
ArcabitTrojan.Razy.D74F7A
GDataGen:Variant.Razy.479098
MAXmalware (ai score=81)
MalwarebytesMalware.Heuristic.1003
RisingMalware.Heuristic!ET#92% (RDMK:cmRtazq+Pco6RxWHP0IJhfyFQk2H)
SentinelOneStatic AI – Suspicious PE
AVGWin32:Evo-gen [Susp]

How to remove Razy.479098 (B)?

Razy.479098 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment