Malware

Razy.897808 (file analysis)

Malware Removal

The Razy.897808 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.897808 virus can do?

  • At least one process apparently crashed during execution
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Razy.897808?


File Info:

name: ED773DAC874681E7CE4A.mlw
path: /opt/CAPEv2/storage/binaries/44abf6322ed961dfacdbc9ebaa2d83df5faecc252abd4878d74f172832ace702
crc32: 135FD6A8
md5: ed773dac874681e7ce4a6e9ed75293dc
sha1: 7dab1785cf9ce48ada29ddac2c3b235d34a6ad67
sha256: 44abf6322ed961dfacdbc9ebaa2d83df5faecc252abd4878d74f172832ace702
sha512: c15d360b5eaffb9db82b8655eaf6fa383da6034be367a9058a0135362bf9b2a7a5327ff67a0fe561129f165c58dfe8220d71e987734039172877318d35b1e50e
ssdeep: 3072:utUwHgCb47NSNj87dciMlOzSvknYYNFopgqu3j+fwGTy3ueM/e0N3iFa9VlvYwJe:0bbScEmSaknYBpwKwGTy3xPFa9VF8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D734CFCA6066CD52E72DB634D2E4DCFAA1163F1DCA869D7B05017D89F9B28C80E33D19
sha3_384: 871e3750ec8dfb2ca54b6680c28379368a037d9a4b1436bf4959c340b228f730c631afe03a2c199abc0ddb51d3b78ccf
ep_bytes: 33c068d1294200c3aba06a98e4c98be4
timestamp: 2011-01-15 00:37:01

Version Info:

CompanyName: Don HO don.h@free.fr
FileDescription: Notepad++ : a free (GNU) source code editor
FileVersion: 5.7
InternalName: npp.exe
LegalCopyright: Copyleft 1998-2006 by Don HO
OriginalFilename: Notepad++.exe
ProductName: Notepad++
ProductVersion: 5.7
Translation: 0x0409 0x04b0

Razy.897808 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Barys.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.ed773dac874681e7
CAT-QuickHealTrojanPWS.Zbot.Y
ALYacGen:Variant.Razy.897808
CylanceUnsafe
VIPRELookslike.Win32.Sirefef.zh (v)
SangforSuspicious.Win32.Barys.54269
K7AntiVirusTrojan ( 004f11e51 )
AlibabaTrojan:Win32/Kryptik.1c69390e
K7GWTrojan ( 0034c9011 )
Cybereasonmalicious.c87468
BitDefenderThetaGen:NN.ZexaF.34212.oC1@ai3pxEci
CyrenW32/FakeNPP.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.ZDG
TrendMicro-HouseCallTSPY_ZBOT.SMES
Paloaltogeneric.ml
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Razy.897808
NANO-AntivirusTrojan.Win32.Kryptik.eddwea
MicroWorld-eScanGen:Variant.Razy.897808
APEXMalicious
TencentMalware.Win32.Gencirc.114bed80
Ad-AwareGen:Variant.Razy.897808
EmsisoftGen:Variant.Razy.897808 (B)
ComodoMalware@#kyrhlal4txxt
ZillyaTrojan.Kryptik.Win32.929519
TrendMicroTSPY_ZBOT.SMES
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
SophosMal/Generic-R + Mal/EncPk-ABFO
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Razy.897808
WebrootW32.Infostealer.Zeus
AviraTR/Dropper.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.TSGeneric
ArcabitTrojan.Razy.DDB310
ZoneAlarmVHO:Hoax.Win32.ArchSMS.gen
MicrosoftPWS:Win32/Zbot!rfn
Acronissuspicious
McAfeeArtemis!ED773DAC8746
VBA32Malware-Cryptor.General.3
MalwarebytesMalware.Heuristic.1008
AvastWin32:Reveton-Y [Trj]
RisingDropper.Generic!8.35E (CLOUD)
YandexTrojan.Kryptik!TwWrCKA8vOA
IkarusTrojan-Spy.Win32.Zbot
FortinetW32/Kryptik.ZFQ!tr
AVGWin32:Reveton-Y [Trj]
PandaBck/Qbot.AO
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Razy.897808?

Razy.897808 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment