Malware

Razy.620065 (B) (file analysis)

Malware Removal

The Razy.620065 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.620065 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Razy.620065 (B)?


File Info:

name: E355DFD57ECC8EA0E758.mlw
path: /opt/CAPEv2/storage/binaries/f6d220f4aad2a27d1c298a12818e87639cc84e9f2282685b974ec1fa9fda80c9
crc32: B3B547D9
md5: e355dfd57ecc8ea0e758c3a7813f55ad
sha1: 585217c7c7b58da3083023c761b6d6bafc0e9be6
sha256: f6d220f4aad2a27d1c298a12818e87639cc84e9f2282685b974ec1fa9fda80c9
sha512: 607e7c9633951e7cb2344f61e1fdd433c902f3ce2b719c794b19521cf905f223054ab6f0a8d7489fdd7622935232b8f69c8e12b338b806c51733b239ec7bc773
ssdeep: 3072:w0gzt9khO1uIfHS1puKYJsZsdSyTih/TisRIxTEs:avSOdfHSnuJJmyTmGsRIxH
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T12714AF27F16A4931DBF60777FCEDB9218EC2A0F61DD3C3F0245098E05E2A2A45BA654D
sha3_384: 96ec5e13fac3c5dafa5178a37bf3796a2a26c698901f00a5596d5eb0f97d3719c2b9ae7767b7f80cc4381f6fa5d96521
ep_bytes: 559461aa05fde52d001cecbc125e8406
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Razy.620065 (B) also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.620065
FireEyeGeneric.mg.e355dfd57ecc8ea0
CAT-QuickHealTrojan.Skeeyah.J1
ALYacGen:Variant.Razy.620065
CylanceUnsafe
ZillyaTrojan.Generic.Win32.206664
K7AntiVirusTrojan ( 005393141 )
K7GWTrojan ( 005393141 )
Cybereasonmalicious.57ecc8
CyrenW32/Kryptik.BQP.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GIRH
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.620065
NANO-AntivirusTrojan.Win32.PackedENT.gxcksd
AvastWin32:MalwareX-gen [Trj]
RisingTrojan.Kryptik!1.B34D (CLASSIC)
Ad-AwareGen:Variant.Razy.620065
SophosML/PE-A + Mal/Inject-GJ
ComodoTrojWare.Win32.Kryptik.TLS@812zm8
DrWebTrojan.PackedENT.123
EmsisoftGen:Variant.Razy.620065 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Selfmod.loc
eGambitUnsafe.AI_Score_99%
AviraHEUR/AGEN.1141086
MAXmalware (ai score=86)
Antiy-AVLTrojan/Generic.ASBOL.C541
ArcabitTrojan.Razy.D97621
GDataGen:Variant.Razy.620065
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.CeeInject.R237089
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34062.lCW@aGdGykg
TACHYONTrojan/W32.Selfmod
VBA32Trojan.Packed
MalwarebytesTrojan.Crypt.Generic
TencentTrojan.Win32.Kryptik.gifya
YandexTrojan.GenAsa!0xM7zILK7cg
IkarusTrojan-Downloader.Win32.FakeAlert
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:MalwareX-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Razy.620065 (B)?

Razy.620065 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment