Malware

Razy.629593 removal tips

Malware Removal

The Razy.629593 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.629593 virus can do?

  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Spanish (Modern)
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Razy.629593?


File Info:

name: C06797D32FB46AFBD679.mlw
path: /opt/CAPEv2/storage/binaries/3da4d68b85a335b3cc5cf8dbe73f8a0b93dc5a9ccd4c1ad7745deb835a3c279c
crc32: F84BDCB5
md5: c06797d32fb46afbd679ea86cdb916f1
sha1: eb745cc7bc5326ceaac5ede58a809885533b1d20
sha256: 3da4d68b85a335b3cc5cf8dbe73f8a0b93dc5a9ccd4c1ad7745deb835a3c279c
sha512: 5c7428a7ddf4c2be8ecda8f345470c482b8f559eff4cc5765b2e7c4009c0a8c9509cb43c7327bdf60faf33698a1eb72e49eb104c17c2f3ed4430a3a5699b692c
ssdeep: 1536:CWuhMFGHo2xtmLdvNOmvBwVf7G+1MPAP0/P:CW8bHnxtmLrOmJwp71M4mP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17D63F753F7A5C937F24BCAB6083686E94132BC3919508907BD057F5E6EB2DC29823E17
sha3_384: 6ba15a68f48d65cce7806d836e618a963101235825dc916a84f170d91e1271a6dbc516c659a8c186387a375945ef98c4
ep_bytes: 68201a4000e8eeffffff000000000000
timestamp: 2011-09-18 21:09:09

Version Info:

Translation: 0x0c0a 0x04b0
CompanyName: BCN
ProductName: pootorro
FileVersion: 1.00
ProductVersion: 1.00
InternalName: stub
OriginalFilename: stub.exe

Razy.629593 also known as:

tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Razy.629593
FireEyeGeneric.mg.c06797d32fb46afb
ALYacGen:Variant.Razy.629593
CylanceUnsafe
VIPREGen:Variant.Razy.629593
SangforSuspicious.Win32.Save.vb
AlibabaTrojanDropper:Win32/Injector.54e565bc
Cybereasonmalicious.32fb46
SymantecTrojan.Gen.2
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.MTC
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Dropper.Win32.Injector.pdvk
BitDefenderGen:Variant.Razy.629593
NANO-AntivirusTrojan.Win32.Gendal.qobny
Ad-AwareGen:Variant.Razy.629593
EmsisoftGen:Variant.Razy.629593 (B)
ComodoTrojWare.Win32.Injector.ADKK@4vyrc7
F-SecureHeuristic.HEUR/AGEN.1242994
DrWebTrojan.Click2.29890
ZillyaTrojan.Injector.Win32.489124
McAfee-GW-EditionArtemis
Trapminemalicious.moderate.ml.score
SophosML/PE-A
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Razy.629593
JiangminTrojanDropper.Injector.bkgr
AviraHEUR/AGEN.1242994
ArcabitTrojan.Razy.D99B59
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win32.ADH.C107812
McAfeeArtemis!C06797D32FB4
RisingTrojan.VBInject!1.64B6 (CLASSIC)
YandexTrojan.Injector!7y+b6r9XVTw
IkarusTrojan.Win32.Buzus
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrypt.C!tr
BitDefenderThetaGen:NN.ZevbaF.34646.em1@aW2hsiN

How to remove Razy.629593?

Razy.629593 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment