Trojan

How to remove “Trojan:Win32/Razy.XA!MTB”?

Malware Removal

The Trojan:Win32/Razy.XA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Razy.XA!MTB virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:Win32/Razy.XA!MTB?


File Info:

name: A4BF1A01FD1EDC017CF4.mlw
path: /opt/CAPEv2/storage/binaries/aa97ce7f6d04e90c3b9d168a6035e00ea2586b01b458eed45b4dee253a1c2941
crc32: 4AC516E9
md5: a4bf1a01fd1edc017cf4f58c17c89f39
sha1: 2ac9ace383f10f5abdbc4655eb3c5523ab192274
sha256: aa97ce7f6d04e90c3b9d168a6035e00ea2586b01b458eed45b4dee253a1c2941
sha512: c6754276dc633af140a9d88f73f5b09645a008a6807a1bb275f6cd151db6e0fee4ba01730a3d13a07a244daf03a992c217cbe61c36067554126938787aeb7206
ssdeep: 3072:oz1fPxQL5rYFAOowL5rWfAXONbANvQwEy91/V+tXnAaPdMgLvSZzYzUf9N:wfJQ9YSOzhetNbo1eAaPdMBzZ
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T12FF3D0A2264B59D0F0EAEEBB43E0C6C653657A935A42532FFE8233A571F399007354F1
sha3_384: 8157ff396b3aa877e6eaa53084b250818f4433f1c12ce97fa6d3239cbeab44fc7286ca90d907f952f78bbae4b6a1e7b4
ep_bytes: b8000000005129f65a01fe21f6465268
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan:Win32/Razy.XA!MTB also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Razy.866116
FireEyeGeneric.mg.a4bf1a01fd1edc01
ALYacGen:Variant.Razy.866116
CylanceUnsafe
VIPREGen:Variant.Razy.866116
K7AntiVirusTrojan ( 0058e60a1 )
K7GWTrojan ( 0058e60a1 )
Cybereasonmalicious.1fd1ed
CyrenW32/Kryptik.ECM.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.XVS
APEXMalicious
ClamAVWin.Packed.Razy-9867637-0
KasperskyHEUR:Trojan.Win32.Copak.vho
BitDefenderGen:Variant.Razy.866116
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Trojan-gen
TencentTrojan.Win32.Copak.zb
Ad-AwareGen:Variant.Razy.866116
EmsisoftGen:Variant.Razy.866116 (B)
DrWebTrojan.Siggen14.40460
ZillyaTrojan.Injector.Win32.1000139
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
Trapminemalicious.high.ml.score
SophosML/PE-A + Troj/Agent-BGOS
IkarusTrojan.Win32.Crypt
GDataGen:Variant.Razy.866116
JiangminTrojan.Copak.lic
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASMalwS.5123
ArcabitTrojan.Razy.DD3744
MicrosoftTrojan:Win32/Razy.XA!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
Acronissuspicious
McAfeeGlupteba-FTSD!A4BF1A01FD1E
VBA32BScope.Trojan.Wacatac
MalwarebytesMalware.AI.4176750019
RisingTrojan.Injector!1.CD26 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.ECM!tr
BitDefenderThetaGen:NN.ZexaF.34786.kuZ@aGo3wXi
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Razy.XA!MTB?

Trojan:Win32/Razy.XA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment