Malware

Razy.607250 (B) (file analysis)

Malware Removal

The Razy.607250 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.607250 (B) virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Razy.607250 (B)?


File Info:

name: B68EE516FDBBD0D50B77.mlw
path: /opt/CAPEv2/storage/binaries/009095da8f5af0312152f7c020c7f8ba3e5086192b19ec2a2cf09b7544f3aaac
crc32: 71A4E8C1
md5: b68ee516fdbbd0d50b77f590ec481805
sha1: 0ff1131fe5baccc17c54a747ce105f9bb5374a16
sha256: 009095da8f5af0312152f7c020c7f8ba3e5086192b19ec2a2cf09b7544f3aaac
sha512: 80aac38a2c03b95454ab72170f5990c93712d5c6ed430401bc76401fbd54ee0eb77a3f427a965088c447e3ffcc1169ff4aa052378bf4931c7734a186487e726e
ssdeep: 24576:xd4YJXtV7C3Lq5CPzNB6CyAysJE7HU9PyrifaQyEzmZ/usOn1ygDj2zskHiq:8YttJ0Lq5OzNMCyAd2UYrifaxZmVn/fs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EE4501C869645357C6F44F3184E2886C39127FB4BEE5915EE43EB78A6F362C318CA50E
sha3_384: d7d2492b41278e8a365755eb7dbfa7c098710f0dc14a45c43d106963f68b7909f57b97b0de2154e0eee2e3aa2e7d94b3
ep_bytes: 1bc080ec0740eb07c9de95f376e1f460
timestamp: 2007-10-15 17:11:00

Version Info:

FileVersion: 5.0.272
ProductVersion: 5.0.272
InternalName: gwctouch
OriginalFilename: gwctouch.exe
CompanyName:
FileDescription: 澳伯斯系统
Comments: 澳伯斯系统
LegalCopyright: 澳伯斯系统
LegalTrademarks: 澳伯斯系统
ProductName: 澳伯斯系统 B1
Translation: 0x0c0a 0x04e4

Razy.607250 (B) also known as:

LionicTrojan.Win32.Razy.4!c
MicroWorld-eScanGen:Variant.Razy.607250
FireEyeGen:Variant.Razy.607250
SkyhighBehavesLike.Win32.Trojan.tc
McAfeeArtemis!B68EE516FDBB
Cylanceunsafe
SangforTrojan.Win32.Razy.Vxf1
Cybereasonmalicious.fe5bac
BitDefenderThetaGen:NN.ZexaF.36680.nz3@aOsb3ini
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Razy.607250
EmsisoftGen:Variant.Razy.607250 (B)
IkarusBackdoor.Win32.Shiz
GDataGen:Variant.Razy.607250
GoogleDetected
Kingsoftmalware.kb.a.985
ArcabitTrojan.Razy.D94412
ALYacGen:Variant.Razy.607250
MAXmalware (ai score=82)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Chgt.AD
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.140254689.susgen
FortinetW32/PossibleThreat
DeepInstinctMALICIOUS

How to remove Razy.607250 (B)?

Razy.607250 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment