Malware

Razy.808469 malicious file

Malware Removal

The Razy.808469 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.808469 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid

How to determine Razy.808469?


File Info:

name: 1FDB95A8E6E06F9F5459.mlw
path: /opt/CAPEv2/storage/binaries/cc84c60272d91850bc2642e47331a8c3a7d7db6cec8a1c26254d845ff14464ae
crc32: 33C8EACC
md5: 1fdb95a8e6e06f9f54591b48b1ecd8dd
sha1: 0bb2e20c5f76d1523a94e39248d19896fe6e41b3
sha256: cc84c60272d91850bc2642e47331a8c3a7d7db6cec8a1c26254d845ff14464ae
sha512: d5afa164173dbe0a0f8e6f2e6fa5be51b5510ae3a2382c71b861385c58f80355d4c735da793bcc6d467ebef0d24511be9804bfdca6fbceb2d8159b2f3b545ea7
ssdeep: 6144:hzExYsBwMX4WD7LXS5xDb3bM8CUshkhFVr63qRK:SYsThD7LXS5x3YrhhYPe3q0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16F54E01566009869F31D4F302A46F8E058A98D3E59E9F50FF17CBE362DB60930AB758F
sha3_384: a47a65b591f058ed56581245402941311c02d1eb05ca276cda06f9678f609f020ecc5378352b3f92d9e9670fd35e10f3
ep_bytes: 538b1d04204000565768040100006878
timestamp: 2012-05-02 16:02:45

Version Info:

0: [No Data]

Razy.808469 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Gimemo.tnBx
ClamAVWin.Trojan.Gimemo-30
McAfeePWS-Zbot.gen.ym
CylanceUnsafe
ZillyaTrojan.Gimemo.Win32.1984
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0055e3991 )
BitDefenderGen:Variant.Razy.808469
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.8e6e06
BitDefenderThetaGen:NN.ZexaF.34682.ruZ@aWOM2Imc
VirITBackdoor.Win32.Andromeda.W
CyrenW32/Gimemo.C.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.QWV
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Gimemo.rms
NANO-AntivirusTrojan.Win32.Gimemo.qtesv
ViRobotTrojan.Win32.A.Gimemo.280103
MicroWorld-eScanGen:Variant.Razy.808469
RisingHackTool.Obfuscator!8.236 (TFE:2:Mm7KYRX3b5M)
Ad-AwareGen:Variant.Razy.808469
TACHYONTrojan/W32.Gimemo.280103
EmsisoftGen:Variant.Razy.808469 (B)
ComodoTrojWare.Win32.Spy.Zbot.DTNY@4pp6dp
DrWebBackDoor.Andromeda.22
VIPREGen:Variant.Razy.808469
McAfee-GW-EditionPWS-Zbot.gen.ym
FireEyeGeneric.mg.1fdb95a8e6e06f9f
SophosML/PE-A + Troj/Zbot-BUF
APEXMalicious
JiangminTrojan/Gimemo.bvu
AviraTR/Ransom.Gimemo.jh
Antiy-AVLTrojan/Generic.ASMalwS.294
MicrosoftVirTool:Win32/Obfuscator.XS
ArcabitTrojan.Razy.DC5615
SUPERAntiSpywareTrojan.Agent/Gen-Kazy
GDataGen:Variant.Razy.808469
GoogleDetected
AhnLab-V3Trojan/Win32.Gimemo.R25158
VBA32Hoax.Gimemo
ALYacGen:Variant.Razy.808469
MAXmalware (ai score=84)
IkarusTrojan-Ransom.Gimemo
PandaTrj/Genetic.gen
TencentMalware.Win32.Gencirc.10b492c2
YandexTrojan.GenAsa!FrwBUB+zndc
SentinelOneStatic AI – Suspicious PE
FortinetW32/Kryptik.WDW!tr
AVGWin32:Citadel [Trj]
AvastWin32:Citadel [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Razy.808469?

Razy.808469 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment