Malware

Should I remove “Razy.589694”?

Malware Removal

The Razy.589694 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.589694 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Arabic (Iraq)
  • Authenticode signature is invalid
  • Behavioural detection: Transacted Hollowing
  • Collects information to fingerprint the system
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Razy.589694?


File Info:

name: 04BEC313D1A43E0FDCA5.mlw
path: /opt/CAPEv2/storage/binaries/e7acb0cb31cf983b31bff4045048dbdb102ebee3f8a65aa5e0d187e9f7746fbc
crc32: 09CD34EE
md5: 04bec313d1a43e0fdca5447a27f75a58
sha1: ae7d079cd1dfc6500751878b4ee62132719c9a5e
sha256: e7acb0cb31cf983b31bff4045048dbdb102ebee3f8a65aa5e0d187e9f7746fbc
sha512: 066ef57ff6e2a43252bb7d98220fd2d94c35e2c20806c914c54db1874d6d656d404b36c85c0be7784ee552c0f7ea3fd30bd6a8cecc6bc8d40acc308cd16a0668
ssdeep: 3072:LiRbuVxBGY4J6tFLHgMr1fOsY1JWOtENy6a:cbyvoWFAPjJm+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T158F37BF8099A903AC73DC979F195F357ABD073BBBA74C8900A47CD47C9E921749B06A0
sha3_384: 841df4f3200f8e26dbbb74127b316aecf20f98c2da89297d8dbaa8b9634d7fa27b17e062dc0ee35aeaad3a1d92246b02
ep_bytes: 558bec81ec20020000c70558b44200b5
timestamp: 2013-09-19 05:21:32

Version Info:

FileDescription: Редактор личных символов
CompanyName: Корпорация Майкрософт
Translation: 0x0419 0x04b0

Razy.589694 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebTrojan.Redirect.175
MicroWorld-eScanGen:Variant.Razy.589694
ClamAVWin.Packed.Shipup-7406467-0
CAT-QuickHealTrojanDropper.Gepys.A
SkyhighBehavesLike.Win32.Generic.ch
ALYacGen:Variant.Razy.589694
Cylanceunsafe
ZillyaDropper.Gepys.Win32.1041
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004363fa1 )
K7GWTrojan ( 004363fa1 )
Cybereasonmalicious.cd1dfc
BitDefenderThetaGen:NN.ZexaF.36738.ku1@a8Svj6lG
VirITTrojan.Win32.Generic.CBS
SymantecPacked.Generic.459
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDropper.Gepys.AA
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.589694
NANO-AntivirusTrojan.Win32.Redirect.cqqrso
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.ShipUp.a
EmsisoftGen:Variant.Razy.589694 (B)
F-SecureHeuristic.HEUR/AGEN.1327223
BaiduWin32.Adware.Kryptik.b
VIPREGen:Variant.Razy.589694
TrendMicroTROJ_KRYPTK.SML2
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.04bec313d1a43e0f
SophosTroj/Agent-ADVT
IkarusTrojan.Win32.ShipUp
GDataWin32.Trojan.PSE.1A73345
JiangminTrojan/ShipUp.vz
GoogleDetected
AviraHEUR/AGEN.1327223
Antiy-AVLTrojan[Dropper]/Win32.Gepys.aa
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Gepys.AA@522ik2
ArcabitTrojan.Razy.D8FF7E
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Vindor!pz
VaristW32/ShipUp.G.gen!Eldorado
AhnLab-V3Trojan/Win32.Agent.R83243
Acronissuspicious
McAfeeTrojan-FDAD!04BEC313D1A4
MAXmalware (ai score=85)
VBA32Trojan.ShipUp
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_KRYPTK.SML2
RisingTrojan.Kryptik!1.A949 (CLASSIC)
YandexTrojan.GenAsa!3l/3m01iHm4
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.ShipUp.gen
FortinetW32/Kryptik.HIJR!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Razy.589694?

Razy.589694 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment