Malware

Razy.151111 malicious file

Malware Removal

The Razy.151111 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.151111 virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Razy.151111?


File Info:

name: BBFD4AEA55305CA4CC9B.mlw
path: /opt/CAPEv2/storage/binaries/fbb19b5a529105a44b5e07e7e4491080182a93f191722e1c636838c2622a66b3
crc32: B820E0FB
md5: bbfd4aea55305ca4cc9bad99fba57cd7
sha1: 38a639abd316b53bceacb39509588b5407a34727
sha256: fbb19b5a529105a44b5e07e7e4491080182a93f191722e1c636838c2622a66b3
sha512: a4be53608485e2e06ce027785f96b1b4f44dac58ae96405012ce043c4c1c986c543254f2570851fe995963b3bbb8ec768012c98fad045f20edd3f609428365f8
ssdeep: 192:xaPMrl/uad6bWnxKD4bjSca3mrnOlk6I36cVQfqa4/aoLawpjKwuwuwuwuwuwuw6:zFWWnvbjScj3LVmXrQAhg3WXVW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14D04ED72E254B3C7D0726D7FF900A9290536B7F78DDA4203AE686E7E25114BDA743A30
sha3_384: 17c6398c0aed449df3b0b049838416e4a8a4c7f0244b409538bceec7ceabf1e7fb827e29aa33b3942c25f320b3507160
ep_bytes: ff250020400000000000000000000000
timestamp: 2018-06-25 20:20:34

Version Info:

Translation: 0x0000 0x04b0
Comments: *Description*
CompanyName: Microsoft
FileDescription: Windows Manager
FileVersion: 0.0.0.0
InternalName: Windows.exe
LegalCopyright: Microsoft
LegalTrademarks: Windows
OriginalFilename: Windows.exe
ProductName: Microsoft Incorporation
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Razy.151111 also known as:

BkavW32.AIDetectNet.01
LionicTrojan.Win32.Generic.4!c
CynetMalicious (score: 99)
FireEyeGeneric.mg.bbfd4aea55305ca4
McAfeeArtemis!BBFD4AEA5530
CylanceUnsafe
VIPREGen:Variant.Razy.151111
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 005080121 )
AlibabaTrojan:MSIL/Generic.45ef7bcd
K7GWTrojan-Downloader ( 005080121 )
Cybereasonmalicious.a55305
CyrenW32/Trojan.DOZ.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.DAY
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Razy-9848022-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.151111
NANO-AntivirusTrojan.Win32.Sysn.emypbp
MicroWorld-eScanGen:Variant.Razy.151111
AvastWin32:Malware-gen
RisingTrojan.Generic/MSIL@AI.97 (RDM.MSIL:2dzm9AFopdkAyVKYlS0gMQ)
Ad-AwareGen:Variant.Razy.151111
EmsisoftGen:Variant.Razy.151111 (B)
ComodoMalware@#7canmplif01y
ZillyaTrojan.Generic.Win32.200051
Trapminemalicious.high.ml.score
SophosML/PE-A
IkarusTrojan-Downloader.MSIL.Agent
GDataGen:Variant.Razy.151111
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1232052
Antiy-AVLTrojan/Generic.ASMalwS.3303
ArcabitTrojan.Razy.D24E47
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:Win32/Bladabindi!ml
GoogleDetected
Acronissuspicious
ALYacGen:Variant.Razy.151111
MAXmalware (ai score=97)
TencentMsil.Trojan-downloader.Agent.Pkhh
YandexTrojan.Agent!vowNSYeHb9w
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.DAY!tr.dldr
BitDefenderThetaGen:NN.ZemsilF.34606.km0@aymkSNg
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Razy.151111?

Razy.151111 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment