Malware

Razy.848414 (B) removal tips

Malware Removal

The Razy.848414 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.848414 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Razy.848414 (B)?


File Info:

name: CA1114749892512792BE.mlw
path: /opt/CAPEv2/storage/binaries/4a8881e75840d5868c44d62d0f87e35e0b7fa2388db3f8ffa6b2ad28d5660d39
crc32: 3F4F71AD
md5: ca1114749892512792bea9d67683d7e6
sha1: f5df6c9348c3c7c6c52a3a5aaa07bcf046dbc33b
sha256: 4a8881e75840d5868c44d62d0f87e35e0b7fa2388db3f8ffa6b2ad28d5660d39
sha512: fe78d813a5629b8b715e59a9685a1122c934fb929bede842e39ecd3ae39882d22ac50f707b9ea9e9df9159b1756115f6b8b51a88444887c315cb3270977cc8f7
ssdeep: 98304:tKXe+eVwySVrw6lijgRQorMoxUlkMl84nux3Skv3SkIDb/YLiP9ZT/2qBXv:8O5w1VrXggRQortxUlX84nrfkCbwLiPl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16F4633C38290C948E7640BBBFD858F41D6FD69C53299045326EE09F6F3B752A90AF361
sha3_384: 9b7d54c43b95b705f566b1e9bd8732cbe89fcbef0c890edca4996ce2c70e4ebea94f660c8e4336fd1762b4a12bd8ba35
ep_bytes: 558bec83c4c05052ff75fc5268493800
timestamp: 2004-02-09 18:43:10

Version Info:

0: [No Data]

Razy.848414 (B) also known as:

Elasticmalicious (high confidence)
DrWebTrojan.SMSSend.4914
MicroWorld-eScanGen:Variant.Razy.848414
FireEyeGeneric.mg.ca11147498925127
ALYacGen:Variant.Razy.848414
CylanceUnsafe
ZillyaTrojan.ArchSMS.Win32.33133
SangforTrojan.Win32.Multsarch.Q
K7AntiVirusTrojan ( 0055dd191 )
AlibabaTrojan:Win32/Multsarch.90ad6123
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.498925
BitDefenderThetaGen:NN.ZexaF.34212.@FZ@aSM4BGoc
VirITTrojan.Win32.SMSSend.HHA
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Kryptik.LTT
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Agent-1242951
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.848414
NANO-AntivirusRiskware.Win32.ArchSMS.ctczzp
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10bf8c78
Ad-AwareGen:Variant.Razy.848414
SophosMal/Generic-S
ComodoMalware@#1jdulcqk917gx
VIPREPacked.Win32.PWSZbot.gen (v)
TrendMicroBKDR_QAKBOT.SMG
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftGen:Variant.Razy.848414 (B)
IkarusVirus.Win32.Heri
GDataGen:Variant.Razy.848414
JiangminTrojan/Generic.antmz
AviraTR/Crypt.XPACK.Gen2
Antiy-AVLTrojan/Win32.SGeneric
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Multsarch.Q
CynetMalicious (score: 100)
McAfeeGenericRXAA-AA!CA1114749892
MAXmalware (ai score=100)
VBA32Trojan.Zeus.EA.0999
TrendMicro-HouseCallBKDR_QAKBOT.SMG
RisingRansom.LockScreen!8.83D (CLOUD)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/Kryptik.LTT!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Razy.848414 (B)?

Razy.848414 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment