Malware

Should I remove “Razy.845520”?

Malware Removal

The Razy.845520 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.845520 virus can do?

  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Creates a copy of itself
  • Deletes executed files from disk

How to determine Razy.845520?


File Info:

name: 856158C1536947FB3355.mlw
path: /opt/CAPEv2/storage/binaries/5de9739e7a2f6b1250d343958a7d1a52409000fdbf288d4bfe362576aa9d5f01
crc32: C455FA4B
md5: 856158c1536947fb3355e12e407d4ec3
sha1: b8f907aaf0d67ff3924338e8e6e3761f588dd5d6
sha256: 5de9739e7a2f6b1250d343958a7d1a52409000fdbf288d4bfe362576aa9d5f01
sha512: 8cbfceb8212e81675c003d31a7fb265b72e41ac9fab4e6e55e47071f4c8aaa00722ce68b1376081da3cd71800499ff5abd411e8bcd781970465e86ff3e6b973f
ssdeep: 6144:RI7aTjZaFxiSaTy3RrMz7LXT2rty+kj/m9jGD3F1Pha:7AinCRAfrMTqmmF15
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B8D4E62E54E82F47EC3CA778A215280C93FFDC92D79CCB8D3F9594C0580EA54AF94969
sha3_384: 391c9a3a02c04e8c3d169785b1767023398117cc8d44804984321177d95b7075153796a1ae7278057701fedb62aaa670
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-04-29 17:37:28

Version Info:

Translation: 0x0000 0x04b0
FileDescription: OSRS_Bot
FileVersion: 1.0.0.0
InternalName: OSRS_Bot.exe
LegalCopyright: Copyright © 2023
OriginalFilename: OSRS_Bot.exe
ProductName: OSRS_Bot
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Razy.845520 also known as:

MicroWorld-eScanGen:Variant.Razy.845520
FireEyeGeneric.mg.856158c1536947fb
ALYacGen:Variant.Razy.845520
MalwarebytesMachineLearning/Anomalous.95%
SangforSuspicious.Win32.Save.a
Cybereasonmalicious.153694
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Kryptik.GNP
APEXMalicious
ClamAVWin.Packed.Downloaderb-7618859-0
KasperskyUDS:Backdoor.MSIL.Bladabindi.gen
BitDefenderGen:Variant.Razy.845520
AvastMSIL:GenMalicious-H [Trj]
RisingMalware.Obfus/MSIL@AI.100 (RDM.MSIL2:UiHfPtcmKEsRmmLeOglKqw)
SophosML/PE-A
F-SecureHeuristic.HEUR/AGEN.1357551
DrWebTrojan.MulDrop21.62538
VIPREGen:Variant.Razy.845520
McAfee-GW-EditionPacked-MR!856158C15369
EmsisoftGen:Variant.Razy.845520 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Razy.845520
GoogleDetected
AviraHEUR/AGEN.1357551
MAXmalware (ai score=87)
ArcabitTrojan.Razy.DCE6D0
ZoneAlarmUDS:Backdoor.MSIL.Bladabindi.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.C4089385
Acronissuspicious
McAfeePacked-MR!856158C15369
Cylanceunsafe
MaxSecureTrojan.Malware.300983.susgen
BitDefenderThetaGen:NN.ZemsilF.36164.Lm0@aKH!LZ
AVGMSIL:GenMalicious-H [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Razy.845520?

Razy.845520 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment