Malware

Razy.500545 removal tips

Malware Removal

The Razy.500545 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.500545 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Executable displays a decoy image
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Created a process from a suspicious location
  • CAPE detected the StormKitty malware family

How to determine Razy.500545?


File Info:

name: 1F0224DB8E28CAF3FF79.mlw
path: /opt/CAPEv2/storage/binaries/e0468c2071f8409b27c686e554484804c1fc768919d3b21ae80ae6e4b85d416c
crc32: B0A13A68
md5: 1f0224db8e28caf3ff79443ef1acb5c2
sha1: 185c419276e0905f8ced5e3baf411646cc87e9b3
sha256: e0468c2071f8409b27c686e554484804c1fc768919d3b21ae80ae6e4b85d416c
sha512: d5214d3c15412183b530b42712cfbce2515edefd491f31f04b2e2a589b3caa9702bc862937f0b4ebd9cb875ac6d1318604f138e70819ccec05c129b56d333067
ssdeep: 6144:PBBNMXq38isHCy/HSyP5MR2fxjHIwNT9i/wf9IJlopL5:PBBsqsz3/VP5MYfqJle
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18F748E325E1BBDC4E37A2C74A50029D50DACEAD793B0917DFB4609AA37E1604DF298F4
sha3_384: 2843e300256d874432fccf5501acc14dc4a5a69382aa9375d27b6fe00ed701c9ca0428aca8016bdbc2e65658c124ae01
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-04-16 21:32:52

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: NFT WIND.exe
LegalCopyright:
OriginalFilename: NFT WIND.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Razy.500545 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.500545
FireEyeGeneric.mg.1f0224db8e28caf3
McAfeeTrojan-FOYS!1F0224DB8E28
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Razy.D7A341
BitDefenderThetaGen:NN.ZemsilF.34606.vm0@aSwPY1h
CyrenW32/MSIL_Agent.BUA.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.DTP
KasperskyHEUR:Trojan-Spy.MSIL.Generic
BitDefenderGen:Variant.Razy.500545
AvastWin32:RATX-gen [Trj]
Ad-AwareGen:Variant.Razy.500545
EmsisoftGen:Variant.Razy.500545 (B)
ComodoTrojWare.MSIL.Noancooe.CDT@7jluau
DrWebTrojan.MulDrop7.47478
SophosML/PE-A + Troj/Mdrop-HZL
APEXMalicious
AviraTR/Dropper.MSIL.Gen
MicrosoftBackdoor:Win32/Bladabindi!ml
GDataGen:Variant.Razy.500545
CynetMalicious (score: 99)
Acronissuspicious
ALYacGen:Variant.Razy.500545
MAXmalware (ai score=89)
MalwarebytesTrojan.Dropper
IkarusTrojan-Dropper.MSIL.Agent
RisingMalware.Obfus/MSIL@AI.100 (RDM.MSIL:B2Fia24xBBpkcAiqSe85CA)
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Agent.CDT!tr
AVGWin32:RATX-gen [Trj]
Cybereasonmalicious.b8e28c

How to remove Razy.500545?

Razy.500545 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment