Malware

About “Razy.60204” infection

Malware Removal

The Razy.60204 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.60204 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Razy.60204?


File Info:

name: DE98BD5C3AFEFEE9149F.mlw
path: /opt/CAPEv2/storage/binaries/7c74d8fabfd6820d13a903669425f4c90fef11a6ae3618d05dcd464a05c9b807
crc32: 43722CAC
md5: de98bd5c3afefee9149f636523d5716c
sha1: 99ae2e45c3582930c92121e41e1a7d011f685127
sha256: 7c74d8fabfd6820d13a903669425f4c90fef11a6ae3618d05dcd464a05c9b807
sha512: e6bf850347fa4da3ddc8c295e91b823fc715c04fc8e9e794748bae949d0e664a1e9ec69aa35f867040500d92db3593ceff4bc0f0b84f5979f8ddca5ec6a92450
ssdeep: 1536:+TQ47kIN54vpiSVr43oQO0QNBLOIBkEEahvywbJLngzQ:arkIrVS8fuBLOk+2bJ0z
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16724B803A216B1E4E82CC87A151732F62BC66C715E0AAD177159FF3738721D47E26B2B
sha3_384: 3ae11038a65bf559e3ad3ba21a9f6c00f630e390c9a81c1ed8e6a6a2a39eea52277b2458ca904cd09701161d2e136232
ep_bytes: 681c554100e8f0ffffff000000000000
timestamp: 1999-12-31 18:49:21

Version Info:

Translation: 0x0409 0x04b0
Psoࡤuct၎ame: ecŴ1
FileVࡥrsion: 00
ProductVersion: 1.00
InternalNam䁥ЀSHURIKEN 3: OၲiginalFilgnam聥
OၲiginalFilgnam聥: IKEN 3.exe

Razy.60204 also known as:

BkavW32.FamVT.SkeeyahY.Trojan
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Brontok
MicroWorld-eScanGen:Variant.Razy.60204
FireEyeGeneric.mg.de98bd5c3afefee9
CAT-QuickHealTrojan.VBCryptVMF.S2726639
ALYacGen:Variant.Razy.60204
CylanceUnsafe
ZillyaWorm.VB.Win32.9
SangforTrojan.Win32.Save.a
K7AntiVirusP2PWorm ( 000032db1 )
K7GWP2PWorm ( 000032db1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZevbaF.34182.om0@ae3pLAdi
VirITWorm.Win32.Brontok.BY
SymantecW32.SillyFDC
ESET-NOD32a variant of Win32/VB.CJ
TrendMicro-HouseCallWORM_VB.FNX
ClamAVWin.Worm.VB-771
KasperskyWorm.Win32.VB.cj
BitDefenderGen:Variant.Razy.60204
NANO-AntivirusTrojan.Win32.VB.crvphq
ViRobotWorm.Win32.VB.229376.D
AvastWin32:Mutama [Wrm]
TencentTrojan.Win32.FakeFolder.tld
SophosML/PE-A
ComodoVirus.Win32.VB.~CFJ@2pmf0
F-SecureWorm.WORM/Bugus.A
BaiduWin32.Worm.VB.j
VIPRETrojan.Win32.Malware (fs)
TrendMicroWORM_VB.FNX
McAfee-GW-EditionBehavesLike.Win32.VBObfus.dm
EmsisoftGen:Variant.Razy.60204 (B)
IkarusWorm.Win32.VB
JiangminWorm/VB.ca
MaxSecureWorm.vb.cj
AviraWORM/Bugus.A
Antiy-AVLWorm/Win32.VB.cj
MicrosoftTrojan:Win32/Brontok.A
ZoneAlarmWorm.Win32.VB.cj
GDataGen:Variant.Razy.60204
CynetMalicious (score: 99)
McAfeeGeneric VB.do
MAXmalware (ai score=81)
VBA32Trojan.VBRA.08344
MalwarebytesWorm.Agent.VB
APEXMalicious
RisingWorm.VBcode!1.6521 (CLASSIC)
YandexTrojan.GenAsa!X2IvD5rBfns
SentinelOneStatic AI – Malicious PE
FortinetW32/VB.54D8!tr
WebrootW32.Worm.Vb.Gen
AVGWin32:Mutama [Wrm]
Cybereasonmalicious.c3afef
PandaTrj/Agent.BOX

How to remove Razy.60204?

Razy.60204 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment