Trojan

Trojan:Win32/Razy.GN!MTB removal tips

Malware Removal

The Trojan:Win32/Razy.GN!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Razy.GN!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan:Win32/Razy.GN!MTB?


File Info:

name: 9C95C25167020A0AB1D1.mlw
path: /opt/CAPEv2/storage/binaries/a2dd7694dae57d3a6afdee821b2867663c045e94e4c1c17c7fffe8cc40dafb05
crc32: 16E0B8AF
md5: 9c95c25167020a0ab1d15aee2cad5f6d
sha1: e50b009ce20fa7770ac554c6105f4cc0590e2d59
sha256: a2dd7694dae57d3a6afdee821b2867663c045e94e4c1c17c7fffe8cc40dafb05
sha512: 81734097dea3a0de6aae0bfdd36daebb21972ead4a99b9a17d5e07e92de11e2c64b475239a4e564f80fbfb65b956a90a1667a029aa2e5746504730262f849aca
ssdeep: 3072:+KPecUIHiJztS/DUnpTtwm7UsbLrX/LbLrkvkoExbrBeRQI0aAz:56qgnp5wsVXL/kvIYQw2
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1FC04126E6676A956E01A38B5E1090885877FFC0FFE8D4B5FC634235C00D18ADA8B39F5
sha3_384: 3eb128cf42355a590381314edbc6b30b3f454a7beabefa246e615a6b54a41e25930184c88ab4510ce8fb5bfecb0fb956
ep_bytes: b9000000005281e8b4afb4d309f889c0
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan:Win32/Razy.GN!MTB also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.865537
FireEyeGeneric.mg.9c95c25167020a0a
McAfeeGlupteba-FUBP!9C95C2516702
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058dcbc1 )
K7GWTrojan ( 0058dcbc1 )
Cybereasonmalicious.167020
BitDefenderThetaGen:NN.ZexaF.34712.kuZ@aejYyMk
CyrenW32/Kryptik.ECM.gen!Eldorado
ESET-NOD32a variant of Win32/Kryptik.XVS
ClamAVWin.Packed.Razy-9928739-0
KasperskyHEUR:Trojan.Win32.Copak.pef
BitDefenderGen:Variant.Razy.865537
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Evo-gen [Susp]
RisingTrojan.Injector!1.C865 (CLASSIC)
Ad-AwareGen:Variant.Razy.865537
EmsisoftGen:Variant.Razy.865537 (B)
ComodoMalCrypt.Indus!@1qrzi1
DrWebTrojan.Siggen17.58474
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
SentinelOneStatic AI – Malicious PE
Trapminemalicious.high.ml.score
SophosML/PE-A + Troj/Agent-BGOS
APEXMalicious
JiangminTrojan.Generic.hhimz
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=84)
MicrosoftTrojan:Win32/Razy.GN!MTB
GDataGen:Variant.Razy.865537
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R435396
Acronissuspicious
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Razy.865537
TACHYONTrojan/W32.Copak.173056.DD
MalwarebytesTrojan.MalPack
TencentTrojan.Win32.Copak.pa
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.ECM!tr
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Razy.GN!MTB?

Trojan:Win32/Razy.GN!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment