Malware

Razy.598597 information

Malware Removal

The Razy.598597 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.598597 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Razy.598597?


File Info:

name: F415568395BE66C28367.mlw
path: /opt/CAPEv2/storage/binaries/0cc35ff6549c97a545f0297949a50fdab0d12d8e9d2cf0ae7c08cce74634e223
crc32: 1E27EFC4
md5: f415568395be66c283673bc6b9aa25f1
sha1: 14f490e3d223b307cea33479644675495bb39ab2
sha256: 0cc35ff6549c97a545f0297949a50fdab0d12d8e9d2cf0ae7c08cce74634e223
sha512: 52be6b520ea3e037afaca8b87752581a6bc3a5043e82f976df028561f6a8d5d7390556affbd083ee31ccee94fc4b1954f8b51ed879fec568fefae92efe915100
ssdeep: 6144:Vq2Xh1kUJzqwCJSIkWke886JaedHFjJiamhuu:A2XTrqlJLkWkeQJ5dlJBmhu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16D4423485DF92735E7E026B7B1B9B530979894229D627071EC6FD30C2E7A5CBC1AC107
sha3_384: fd4325b6668444ccff79056641cc81f3dce2925bcaaa0f79f81a6319e5545a70edfe720779a2cc984d9f5b2e948f3a20
ep_bytes: 60be00c044008dbe0050fbff57eb0b90
timestamp: 2008-07-20 12:04:51

Version Info:

CompanyName: Gifts Plays
FileDescription: Bring Spook Silver
FileVersion: 85.82.125.47
InternalName: Bridge
LegalCopyright: Copyright © Link Mail 2002-2005
OriginalFilename: Mum.exe
ProductName: Deer
ProductVersion: 85.82.125.47
Translation: 0x0409 0x04b0

Razy.598597 also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.f415568395be66c2
ALYacGen:Variant.Razy.598597
CylanceUnsafe
SangforTrojan.Win32.Krajabot.atG
K7AntiVirusTrojan ( 0055e3991 )
AlibabaRansom:Win32/Obfuscator.5f5c87dd
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.395be6
BitDefenderThetaAI:Packer.9A32622A1F
VirITTrojan.Win32.Winlock.EYF
CyrenW32/Zbot.DA.gen!Eldorado
SymantecTrojan.Gen
ESET-NOD32a variant of Win32/Kryptik.QLA
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.598597
NANO-AntivirusTrojan.Win32.Gimemo.dtjzh
MicroWorld-eScanGen:Variant.Razy.598597
APEXMalicious
TencentWin32.Trojan.Generic.Eacr
Ad-AwareGen:Variant.Razy.598597
SophosMal/Generic-R + Mal/EncPk-AAG
ComodoTrojWare.Win32.Trojan.XPACK.Gen@2ho5ur
DrWebTrojan.Winlock.3333
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
EmsisoftGen:Variant.Razy.598597 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Razy.598597
JiangminTrojan/Gimemo.wq
WebrootW32.Trojan.Gen
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.C2B1CF
KingsoftWin32.Troj.Undef.(kcloud)
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Ransom.DR
McAfeeArtemis!F415568395BE
VBA32Trojan.Zeus.EA.0999
AvastFileRepMetagen [Malware]
RisingWorm.Delf!8.1B3 (CLOUD)
YandexTrojan.Kryptik!qL6fjB/TxQY
IkarusWin32.SuspectCrc
MaxSecureTrojan.Malware.2423278.susgen
FortinetW32/Injector.HVQ!tr
AVGFileRepMetagen [Malware]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Razy.598597?

Razy.598597 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment