Malware

Razy.984680 (B) removal guide

Malware Removal

The Razy.984680 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.984680 (B) virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Razy.984680 (B)?


File Info:

name: 5704674B349EE23EC9F4.mlw
path: /opt/CAPEv2/storage/binaries/1003b741b70a156379e515e5e3553f4b7b062396a5bd47192f78fe95ff13bd02
crc32: 5EFE9BA6
md5: 5704674b349ee23ec9f49a32b74a4fe7
sha1: db5cd5177d7feca229acee74117814a893025a09
sha256: 1003b741b70a156379e515e5e3553f4b7b062396a5bd47192f78fe95ff13bd02
sha512: 596a1b3069a9ed4d29c1f51ec6bc9bc6940b6dd24db998b4a2c5e85eeed075627305a17631466c65d1138e6092e62c60c30051a83dde87c174e7071b08d52a0f
ssdeep: 24576:HigRBopNlhXIkk+e/wUj96H0HkCIabjKoh9WJA5SxzfadB3IdAuDzxW:FgNlo/IJHLCIabjKoh9WJlydB3IxDzx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16CC5F622BADFEB22CC3811B15F7D869249606C8407D1C393B6A47E2DD9335A8767F217
sha3_384: 58ade39cec09fbc5f29aecfac65949252d1f56dac955ba4a9de1942c4dd37a0bb7e6193acd6c0ba55c475f4ad01b811b
ep_bytes: 0489442408893c2489f1e88b0203008b
timestamp: 2018-02-07 07:38:46

Version Info:

0: [No Data]

Razy.984680 (B) also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner.547
MicroWorld-eScanGen:Variant.Razy.984680
FireEyeGen:Variant.Razy.984680
ALYacGen:Variant.Razy.984680
SangforTrojan.Win32.Save.a
K7GWHacktool ( 700007861 )
CyrenW32/Agent.DMZ.gen!Eldorado
TrendMicro-HouseCallTROJ_GEN.R03BC0PLN21
ClamAVWin.Worm.Vindor-9886047-0
BitDefenderGen:Variant.Razy.984680
AvastWin64:Evo-gen [Susp]
Ad-AwareGen:Variant.Razy.984680
EmsisoftGen:Variant.Razy.984680 (B)
TrendMicroTROJ_GEN.R03BC0PLN21
McAfee-GW-EditionBehavesLike.Win32.Generic.vm
SophosGeneric ML PUA (PUA)
IkarusTrojan.Generic
GDataGen:Variant.Razy.984680
JiangminPacked.Krap.gvuf
MAXmalware (ai score=89)
Antiy-AVLTrojan/Generic.ASMalwS.34F17F5
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.VG.R459460
McAfeeGenericRXQV-VG!5704674B349E
VBA32Worm.AutoRun
MalwarebytesMalware.AI.3696146603
RisingWorm.VB!1.DA41 (CLASSIC)
YandexTrojan.Agent!K/4zi0l+eFg
SentinelOneStatic AI – Malicious PE
FortinetW32/Agent.5196!tr
AVGWin64:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_80% (W)

How to remove Razy.984680 (B)?

Razy.984680 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment