Malware

Razy.662483 removal

Malware Removal

The Razy.662483 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.662483 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify proxy settings
  • Deletes executed files from disk

How to determine Razy.662483?


File Info:

name: 99100C7648057C8D7EAA.mlw
path: /opt/CAPEv2/storage/binaries/00f78f490bd3140c59bf1e96a3f7e77fbb04223e0961d29a9aab28d34199af23
crc32: 66E1DA77
md5: 99100c7648057c8d7eaa7bfee54780ca
sha1: 7cacd47495d2b9c8644acb960714cd3fbddc0780
sha256: 00f78f490bd3140c59bf1e96a3f7e77fbb04223e0961d29a9aab28d34199af23
sha512: bf63c477b69b3437e87b382bb69f1f22bd84d35684094e1b4e5745c9631230000d48db5d89316fa26bf5b046dcb04ddb83e5af19275a5d2ce08fe100b7306af1
ssdeep: 49152:b7D9QNJRJUWrmnCkwIsvao9q3vMn0yFOQGwVaeRVSgVtrs+TD2GqbW1:pgRJUemCksn9dFOsfVSgbRqbm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F3C5330381B8F75ECDAB473440959DC14BB3580AB557C24B92B0EF9805EB8A4FF49FA6
sha3_384: 99e8ff838b0b5a715077ed1ed93c2d997440d83a0d20fd3bf19ab13b9b038298f8897f6f7569fd10674cd269ead78414
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-08-22 12:20:02

Version Info:

Translation: 0x0000 0x04b0
Comments: KEsTnL7Q
CompanyName: UA0HUGY2
FileDescription: KEsTnL7Q
FileVersion: 18.21.10.15
InternalName: Public.exe
LegalCopyright: OEvtuDwN
LegalTrademarks: WKAqUMy8
OriginalFilename: Public.exe
ProductName: 6qfI4CHx
ProductVersion: 18.21.10.15
Assembly Version: 26.21.15.17

Razy.662483 also known as:

BkavW32.AIDetectNet.01
CynetMalicious (score: 99)
FireEyeGeneric.mg.99100c7648057c8d
McAfeeGenericRXGR-VD!99100C764805
MalwarebytesMalware.AI.3842825576
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0049ff201 )
K7GWTrojan ( 0049ff201 )
Cybereasonmalicious.648057
CyrenW32/MSIL_Injector.KX.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Injector.SM
APEXMalicious
ClamAVWin.Packed.Gamarue-6989496-0
KasperskyHEUR:Trojan.MSIL.Reconyc.gen
BitDefenderGen:Variant.Razy.662483
MicroWorld-eScanGen:Variant.Razy.662483
AvastWin32:Agent-AOHY [Trj]
RisingTrojan.Tiggre!8.ED98 (CLOUD)
Ad-AwareGen:Variant.Razy.662483
EmsisoftGen:Variant.Razy.662483 (B)
DrWebBackDoor.Comet.152
VIPREGen:Variant.Razy.662483
McAfee-GW-EditionGenericRXGR-VD!99100C764805
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Razy.662483
AviraTR/Dropper.Gen
ArcabitTrojan.Razy.DA1BD3
MicrosoftBackdoor:Win32/Bladabindi!ml
GoogleDetected
AhnLab-V3Dropper/Win32.Dapato.C146841
Acronissuspicious
BitDefenderThetaAI:Packer.A9C1D37A1F
ALYacGen:Variant.Razy.662483
MAXmalware (ai score=81)
VBA32Trojan.Downloader
CylanceUnsafe
IkarusVirus.ILCrypt
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/TrojDropper.AE!tr
AVGWin32:Agent-AOHY [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Razy.662483?

Razy.662483 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment