Malware

Razy.607347 removal guide

Malware Removal

The Razy.607347 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.607347 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Razy.607347?


File Info:

name: 87CEA8BC1BCEDEFF457C.mlw
path: /opt/CAPEv2/storage/binaries/a5fdd7c84ffb43834aab894f665ad35f18daa5dad7c0a643c13eb6cb32d16bd1
crc32: 39A58E93
md5: 87cea8bc1bcedeff457c9a32825412c7
sha1: 74764e51e4d58c153f56afe1d4a59b5dc86a67a0
sha256: a5fdd7c84ffb43834aab894f665ad35f18daa5dad7c0a643c13eb6cb32d16bd1
sha512: fda4e1c2ba2734feeb08ce07d00a9ecbabaabb862d4f5baa39ede7f93eb0d5dfcde7d6d53920f681b83630ad6ba8545a67504f9c529cd126d9e758ffce4ac4f4
ssdeep: 6144:kPBAHBxQl+MqlLyD5E956KolsO1wmsWYMyY6e/sGU8R:kPBOBxQl+HRyD69YPlzwCYBSLU8R
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11B747D3178908231E163A8798925E36E896FB8317C685A5B37DC1E7D8F74090B727F27
sha3_384: 17f767e1de5170662528abf7d23d4b0c1de9b1ebbbd6f0762ed4256ed6aa8c214aadf704f5c9d6c8c52843541d579142
ep_bytes: e86d050000e9000000006a146880a543
timestamp: 2020-02-03 19:42:18

Version Info:

0: [No Data]

Razy.607347 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Graftor.4!c
MicroWorld-eScanGen:Variant.Razy.607347
FireEyeGeneric.mg.87cea8bc1bcedeff
ALYacGen:Variant.Razy.607347
MalwarebytesMalware.Heuristic.1001
VIPREGen:Variant.Razy.607347
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0055f78f1 )
AlibabaAdWare:Win32/AdLoad.80f15afc
K7GWTrojan ( 0055f78f1 )
Cybereasonmalicious.c1bced
ArcabitTrojan.Razy.D94473
BitDefenderThetaGen:NN.ZexaF.36318.uGW@aaTbb!ai
CyrenW32/Agent.BPR.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HAVV
APEXMalicious
KasperskyHEUR:Trojan-Downloader.Win32.Adload.vho
BitDefenderGen:Variant.Razy.607347
NANO-AntivirusTrojan.Win32.DownLoad4.gzagys
ViRobotTrojan.Win.Z.Adload.340992
AvastWin32:TrojanX-gen [Trj]
TencentMalware.Win32.Gencirc.10b51c8d
EmsisoftGen:Variant.Razy.607347 (B)
F-SecureHeuristic.HEUR/AGEN.1318622
DrWebTrojan.DownLoad4.13317
ZillyaDownloader.Adload.Win32.93726
TrendMicroMal_TRICKBOTSTR01
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
JiangminTrojanDownloader.Adload.zvj
GoogleDetected
AviraHEUR/AGEN.1318622
MAXmalware (ai score=83)
Antiy-AVLTrojan[Downloader]/Win32.Adload
XcitiumMalware@#3bq0x14oviofd
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan-Downloader.Win32.Adload.vho
GDataGen:Variant.Razy.607347
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Trickbotstr01.R326929
McAfeeGenericRXJR-KM!87CEA8BC1BCE
VBA32TrojanDownloader.Adload
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallMal_TRICKBOTSTR01
RisingTrojan.GenKryptik!8.AA55 (TFE:5:3fefglPx5bB)
IkarusTrojan.Win32.Crypt
FortinetW32/Injector.EKHF!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Razy.607347?

Razy.607347 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment