Malware

Razy.540499 (B) removal tips

Malware Removal

The Razy.540499 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.540499 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Razy.540499 (B)?


File Info:

name: 43557E1A2666CA2C57C7.mlw
path: /opt/CAPEv2/storage/binaries/c6c091a2c0fd62cf432e9296268c949f7b20da5860cb1cdc5404ca972ae571ab
crc32: 7B76410F
md5: 43557e1a2666ca2c57c701f64f7aad67
sha1: 139c698879f6a3016b50f0a062cb7ad468af26e8
sha256: c6c091a2c0fd62cf432e9296268c949f7b20da5860cb1cdc5404ca972ae571ab
sha512: 9bc20d9dff6725e52eca6a825413461737926cf1ee9775662356e1cf298c45856eb234db2e109e20855855d74841d2c4b5491eb6bf1c99dd4c97b213c0c00036
ssdeep: 1536:SyQla/zaRkOjn0GytfMlIXoJbkZzai955Yovydo0NLjN:jtqlyYIjzai9rY/h
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AAD3ED2E1D9D46D3F4BBFB7AB26448764679680FEF4E72CC9D0CE0053887A64D894E12
sha3_384: 20c1922543c6bf46bf5b75ce387b0d07599057639a8bf60fde609e912d1ced51f80654df7284b5a73da5d7df39666daa
ep_bytes: 31c05031c05668162040006811204000
timestamp: 2011-07-31 20:31:47

Version Info:

0: [No Data]

Razy.540499 (B) also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Razy.540499
ClamAVWin.Malware.Razy-9777714-0
FireEyeGeneric.mg.43557e1a2666ca2c
McAfeeGenericRXEP-JW!43557E1A2666
Cylanceunsafe
ZillyaWorm.AutoRun.Win32.116743
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 000136ec1 )
K7GWTrojan ( 000136ec1 )
Cybereasonmalicious.a2666c
CyrenW32/Scar.AF.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/AutoRun.Agent.ADK
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Worm.Win32.AutoRun.gen
BitDefenderGen:Variant.Razy.540499
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:WormX-gen [Wrm]
EmsisoftGen:Variant.Razy.540499 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebWin32.HLLW.Autoruner3.7144
VIPREGen:Variant.Razy.540499
McAfee-GW-EditionBehavesLike.Win32.Generic.ct
Trapminemalicious.high.ml.score
SophosTroj/Agent-BFRF
IkarusWorm.Win32.AutoRun
GDataGen:Variant.Razy.540499
JiangminTrojan/Generic.bgbgt
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.AGeneric
ArcabitTrojan.Razy.D83F53
ZoneAlarmHEUR:Worm.Win32.AutoRun.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win32.Scar.C60091
Acronissuspicious
VBA32BScope.Trojan.Tiggre
ALYacGen:Variant.Razy.540499
MalwarebytesWorm.AutoRun.Generic
PandaTrj/Genetic.gen
RisingWorm.Autorun!1.CD41 (CLASSIC)
YandexTrojan.Agent!wiOGmI6N+u8
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.ADK!tr
BitDefenderThetaGen:NN.ZexaF.36164.imX@aW1ea!i
AVGWin32:WormX-gen [Wrm]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Razy.540499 (B)?

Razy.540499 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment