Malware

Razy.151134 removal guide

Malware Removal

The Razy.151134 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.151134 virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Razy.151134?


File Info:

name: 8C0BEDCD152F226DD266.mlw
path: /opt/CAPEv2/storage/binaries/fb01390b4b4280acb801d40d339f9d773d5d555e66ec00bae79a9a684d4ba234
crc32: FC709C6D
md5: 8c0bedcd152f226dd2661ab6897a3908
sha1: 8e3f9f79d7ee4b2cb82069e6205962ee51feb4ff
sha256: fb01390b4b4280acb801d40d339f9d773d5d555e66ec00bae79a9a684d4ba234
sha512: 25e4df7eeb003d68355b9261ac337f5a00c3f1e924feb3a725211b9e7dcce8b174cb6807abd7ed626dfc796bb81e1b145dac31578b6e86f888d10f02f2d705f9
ssdeep: 768:edGPMb8oA4LoYm5SfQBE3b/HFRIXG/cEF:7PR8osom3b/HFRIXucEF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T152D2085767E89723EB3D2B7940621A054BF6CD254662FF2E3D8435E80CF770A4B81A87
sha3_384: 2b9e97ed18fe523a015c99636b283695e2ee9483dc46a09e9daa9211a3a6d947071f7ef96cee204a4e7d376d474097ce
ep_bytes: ff250020400000000000000000000000
timestamp: 2017-05-15 21:11:24

Version Info:

Translation: 0x0000 0x04b0
CompanyName: Microsoft
FileDescription: server
FileVersion: 1.0.0.0
InternalName: server.exe
LegalCopyright: Copyright © Microsoft 2017
OriginalFilename: server.exe
ProductName: server
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Razy.151134 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.151134
FireEyeGeneric.mg.8c0bedcd152f226d
ALYacGen:Variant.Razy.151134
MalwarebytesBackdoor.Bladabindi
ZillyaDropper.Agent.Win32.443033
SangforTrojan.MSIL.Agent.AKH
K7AntiVirusTrojan ( 004971411 )
BitDefenderGen:Variant.Razy.151134
K7GWTrojan ( 004971411 )
Cybereasonmalicious.d152f2
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.AKH
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Backdoor.MSIL.Generic
AlibabaBackdoor:MSIL/Generic.869d16b7
NANO-AntivirusTrojan.Win32.Disfa.epwwrf
RisingTrojan.Generic/MSIL@AI.98 (RDM.MSIL:k6Rpljf+ez19XOgygC2tbg)
Ad-AwareGen:Variant.Razy.151134
SophosMal/Generic-S
ComodoTrojWare.MSIL.Dynamer.AS@7ewb3t
DrWebTrojan.DownLoader23.23307
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
EmsisoftGen:Variant.Razy.151134 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.MSIL.cych
AviraHEUR/AGEN.1101191
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASMalwS.20BCEC6
MicrosoftTrojan:Win32/Dynamer!rfn
ZoneAlarmHEUR:Backdoor.MSIL.Generic
GDataGen:Variant.Razy.151134
CynetMalicious (score: 99)
McAfeeArtemis!8C0BEDCD152F
VBA32TScope.Trojan.MSIL
CylanceUnsafe
PandaTrj/GdSda.A
TencentMsil.Backdoor.Generic.Eadn
YandexTrojan.Disfa!4pIWKhZA/wo
IkarusTrojan-Dropper
eGambitUnsafe.AI_Score_99%
FortinetMSIL/Agent.CUA!tr.dldr
BitDefenderThetaGen:NN.ZemsilF.34182.bq0@aafpZDf
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Razy.151134?

Razy.151134 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment