Trojan

Trojan:Win32/Razy.CD!MTB malicious file

Malware Removal

The Trojan:Win32/Razy.CD!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Razy.CD!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Transacted Hollowing
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan:Win32/Razy.CD!MTB?


File Info:

name: AC115CD4FA41787DFB6E.mlw
path: /opt/CAPEv2/storage/binaries/84a365303d3afd89aa7b41bcfb1a794adb8bad582bebccc1cd12bff15a3e164f
crc32: B6C69132
md5: ac115cd4fa41787dfb6e3d4101daf94a
sha1: bf0cf80a27d857c0e90c771e1a8c04d42c2aafe8
sha256: 84a365303d3afd89aa7b41bcfb1a794adb8bad582bebccc1cd12bff15a3e164f
sha512: 461309741e64d962252505cef3082e456abe4c2e8b4de30e44602209d40daa2d8f63acaa10c4888479dc102e11fbb640f54e9cb82c74c717001fa57ea262f6a1
ssdeep: 12288:seLJFGMde35/Isr39dpTOPax4dUU0nSDbDjI:sC7Q319RTigOgnS3DE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10BB4E0CB1DDAEB03D22F9FF656CC5C8319ED5406E464B2E9D6E1287623262CCD8F41A1
sha3_384: 0c77752ad4eb45d06f2eacda708ecb6b2261e78767581a97199e08d65f28d5beef354ca967631ac5cd31f4925f8e9a04
ep_bytes: b8000000005681c20100000021d28b3c
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan:Win32/Razy.CD!MTB also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
FireEyeGeneric.mg.ac115cd4fa41787d
McAfeeGlupteba-FTTQ!AC115CD4FA41
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
BitDefenderGen:Variant.Razy.373115
K7GWTrojan ( 00577ea11 )
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/Kryptik.ECA.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GJIX
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanGen:Variant.Razy.373115
RisingMalware.Heuristic!ET#98% (RDMK:cmRtazo0u0ALx3kfXlKgSbX6xy/O)
Ad-AwareGen:Variant.Razy.373115
SophosML/PE-A + Troj/Agent-BGOS
ComodoMalCrypt.Indus!@1qrzi1
TrendMicroTROJ_GEN.R03BC0DB122
McAfee-GW-EditionBehavesLike.Win32.Glupteba.hc
EmsisoftGen:Variant.Razy.373115 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Razy.373115
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASMalwS.3514F65
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Razy.CD!MTB
AhnLab-V3Malware/Win32.RL_Generic.R299848
BitDefenderThetaAI:Packer.E97B5BBC1E
ALYacGen:Variant.Razy.373115
VBA32BScope.Trojan.Wacatac
TrendMicro-HouseCallTROJ_GEN.R03BC0DB122
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.ECM!tr
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.4fa417
AvastWin32:Evo-gen [Susp]

How to remove Trojan:Win32/Razy.CD!MTB?

Trojan:Win32/Razy.CD!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment