Malware

Razy.594846 removal tips

Malware Removal

The Razy.594846 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.594846 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Unconventionial language used in binary resources: Korean
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Razy.594846?


File Info:

name: 61157D2CA35CA8700009.mlw
path: /opt/CAPEv2/storage/binaries/c3c427f76add9ca5e59ff6296a54ab232c1674e2bd31e80d10d4504cb2f34618
crc32: 513E8729
md5: 61157d2ca35ca870000923dfe1bff98d
sha1: 0a0b8ef2b3f6bd5ad7cce17165d52568f230faa4
sha256: c3c427f76add9ca5e59ff6296a54ab232c1674e2bd31e80d10d4504cb2f34618
sha512: cb257f1527739a6018d106258d47d33ef67173ad8dc4ae33ecff50569602a040a244d1d80b8f49ef9fa79add5b685d3b907e0711fed39a540edd14bc25f449b0
ssdeep: 384:s1K3yL2pQnVDFO57S5S+PNko/IcqHx4onc9niOu9Io61BhwFY/bmkekE5W1HTbvb:sHiaDk76SoAXRTcVPK61vRp1753S1Oa2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E3F2E1C497BDB156D6BE2A700093E6128FD8FD22F73E817B6E6037897A14B208611B90
sha3_384: 39fb223bded996298fe6d45b1d89393917ec3e10f1acbc483b71a2391ace30d73fdb7d3ff4ca18089b052e476df7c1b7
ep_bytes: 60be006040008dbe00b0ffff5783cdff
timestamp: 2007-09-05 15:33:49

Version Info:

Comments:
CompanyName:
FileDescription: dawa MFC 응용 프로그램
FileVersion: 1, 0, 0, 1
InternalName: dawa
LegalCopyright: Copyright (C) 2007
LegalTrademarks:
OriginalFilename: dawa.EXE
PrivateBuild:
ProductName: dawa 응용 프로그램
ProductVersion: 1, 0, 0, 1
SpecialBuild:
Translation: 0x0412 0x04b0

Razy.594846 also known as:

LionicTrojan.Win32.Agent.b!c
MicroWorld-eScanGen:Variant.Razy.594846
FireEyeGeneric.mg.61157d2ca35ca870
McAfeeGenericRXAA-AA!61157D2CA35C
VIPREGen:Variant.Razy.594846
SangforSuspicious.Win32.Save.a
Cybereasonmalicious.ca35ca
CyrenW32/Virut.AI.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Razy.594846
AvastWin32:Patched-AFR [Trj]
TencentWin32.Trojan-Dropper.Agent.bktx
Ad-AwareGen:Variant.Razy.594846
SophosGeneric ML PUA (PUA)
ComodoMalware@#p2qefn64yooj
DrWebTrojan.MulDrop2.32274
ZillyaDropper.Agent.Win32.99432
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Razy.594846 (B)
GDataGen:Variant.Razy.594846
JiangminTrojanDropper.Agent.ayqg
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASMalwS.3C54
ViRobotDropper.Agent.36864.Y
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34592.cmKfa0ndABeG
ALYacGen:Variant.Razy.594846
VBA32BScope.TrojanDownloader.VB
MalwarebytesSality.Virus.FileInfector.DDS
YandexTrojan.DR.Agent!/nVb+ajDMZw
IkarusVirus.Win32.Virut
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.EYDL!tr
AVGWin32:Patched-AFR [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Razy.594846?

Razy.594846 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment