Malware

Razy.707386 removal guide

Malware Removal

The Razy.707386 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.707386 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Appears to use command line obfuscation
  • Deletes executed files from disk
  • Harvests cookies for information gathering
  • Harvests credentials from local FTP client softwares
  • Uses suspicious command line tools or Windows utilities

How to determine Razy.707386?


File Info:

name: 15EE8D3F04BB030B4A47.mlw
path: /opt/CAPEv2/storage/binaries/f681e2c115505b99346acafbbb52281dfbfca1cc3b5690e9ac6c0072b7b67d8e
crc32: EF329489
md5: 15ee8d3f04bb030b4a47a5792dc8f377
sha1: 4694f7ca2ebeea446c1a9877af6e531fc2140e4e
sha256: f681e2c115505b99346acafbbb52281dfbfca1cc3b5690e9ac6c0072b7b67d8e
sha512: fed0aaae134da3cf40f637f20886aff62b26f1fe8e56f2d9c983895420d97b92c10975792bf2eb629e1a06a9455d8afce02ed588144f31af918745911721070c
ssdeep: 1536:z4wq1LiBLnb3ZyMzZ2w8c0OOOBrX6utTeuO6AFlzpv:EwqYhrDZ2G0ObX6utyfFlzpv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EA8302199AEC3ADFD0FB8BB66E7037352422F47082F2CBAE0185565B353362862D1675
sha3_384: c28752d9793ecbf24086de1adc8d9cac7057b3ae335fb1db58e39d5a2f62e0fd2d790298f24f0e5aa3e9897e5e7d536f
ep_bytes: 60be00e043008dbe0030fcff5783cdff
timestamp: 1994-10-21 03:40:07

Version Info:

CompanyName:
FileDescription: SDL_ttf
FileVersion: 2, 0, 7, 0
InternalName: SDL_ttf
LegalCopyright: Copyright © 2002 Sam Lantinga
OriginalFilename: SDL_ttf.dll
ProductName: Simple DirectMedia Layer
ProductVersion: 2, 0, 7, 0
Translation: 0x0409 0x04b0

Razy.707386 also known as:

LionicTrojan.Win32.CodecPack.lhMQ
MicroWorld-eScanGen:Variant.Razy.707386
CAT-QuickHealTrojanDownloader.Stegvob.AA3
McAfeeArtemis!15EE8D3F04BB
CylanceUnsafe
ZillyaTrojan.Pasmu.Win32.471
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0054cb111 )
AlibabaTrojanPSW:Win32/Codtree.6c2800f1
K7GWTrojan ( 0054cb111 )
Cybereasonmalicious.f04bb0
BaiduWin32.Trojan.Kryptik.adl
CyrenW32/Zbot.BX.gen!Eldorado
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Kryptik.QSL
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Razy-7004488-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.707386
NANO-AntivirusTrojan.Win32.Pasmu.exzxg
AvastFileRepMalware [Misc]
TencentWin32.Trojan.Generic.Ocnw
Ad-AwareGen:Variant.Razy.707386
ComodoTrojWare.Win32.Spy.Zbot.GC@4knng6
DrWebTrojan.Packed.21790
VIPREGen:Variant.Razy.707386
McAfee-GW-EditionBehavesLike.Win32.Sytro.mc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.15ee8d3f04bb030b
SophosML/PE-A + Mal/Bredo-O
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Razy.707386
WebrootW32.Trojan.Gen
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.3303
ArcabitTrojan.Razy.DACB3A
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win32.Zbot.R7346
VBA32BScope.Trojan.Zbot.01367
ALYacGen:Variant.Razy.707386
RisingSpyware.Zbot!8.16B (TFE:5:xDcIGLSyOQQ)
YandexTrojan.Pasmu!4p2q9zWlDKQ
IkarusTrojan.Win32.Meredrop
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Bredo.P!tr
BitDefenderThetaGen:NN.ZexaF.34698.fmKfayRHbfj
AVGFileRepMalware [Misc]
PandaTrj/Banker.JJG
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Razy.707386?

Razy.707386 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment