Malware

Razy.158071 removal

Malware Removal

The Razy.158071 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.158071 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Razy.158071?


File Info:

name: 7340730AE379D965A644.mlw
path: /opt/CAPEv2/storage/binaries/db86c3cb85881c2e92df1f92ffdce9fb40e220bf133bc6f4c5be6c7426de4868
crc32: 1800AF7F
md5: 7340730ae379d965a644592bff8ae5e8
sha1: 21f1859d94b506a34889c4b42eb78eae2b067273
sha256: db86c3cb85881c2e92df1f92ffdce9fb40e220bf133bc6f4c5be6c7426de4868
sha512: b95217fcfe3d941adfabc226e7c225f9f4d8c425c0825eebb97eb6918ab3f852e5ceec5c45d0d51bfdac41aa11c7c06147afb3943fd532a59d8103d4d43c4766
ssdeep: 96:EMhG7K/zHgxQMPjDnzQoD51RbkuUaLn/IW0phIR2ZFRHO9icYDXhy27:3hGayDQuRbRNbw7hIRqpOMhX7
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1BFE18E17F82C5E7BC7D25E7B2247120162BCD58547BBA379B7B9613860AB160443AF30
sha3_384: 3d293c4b5deef87f30e35805d1963c0af8c6d2e9d1bf5e1cea092971d23f4ee99e408fd93c2b9a46b24d6ef74722398d
ep_bytes: 60be006040008dbe00b0ffff5783cdff
timestamp: 2012-01-24 09:51:25

Version Info:

0: [No Data]

Razy.158071 also known as:

LionicHeuristic.File.Generic.00×1!p
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Razy.158071
FireEyeGeneric.mg.7340730ae379d965
McAfeeArtemis!7340730AE379
CylanceUnsafe
ZillyaBackdoor.BotNet.Win32.8
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 001497881 )
K7GWTrojan ( 001497881 )
Cybereasonmalicious.ae379d
BitDefenderThetaGen:NN.ZexaF.34606.amGfaOwYi5h
CyrenW32/Trojan.HJH.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Zeus.B
TrendMicro-HouseCallCryp_Xin1
ClamAVWin.Trojan.Zbot-9838722-0
KasperskyBackdoor.Win32.BotNet.dv
BitDefenderGen:Variant.Razy.158071
NANO-AntivirusTrojan.Win32.TrjGen.cuvfjj
CynetMalicious (score: 100)
AvastWin32:Evo-gen [Trj]
Ad-AwareGen:Variant.Razy.158071
EmsisoftGen:Variant.Razy.158071 (B)
ComodoMalware@#cdbbacap75qp
DrWebBackDoor.Siggen.50423
VIPREGen:Variant.Razy.158071
TrendMicroCryp_Xin1
McAfee-GW-EditionBehavesLike.Win32.Agent.zc
Trapminemalicious.moderate.ml.score
SophosMal/Zbot-FU
APEXMalicious
GDataGen:Variant.Razy.158071
JiangminBackdoor/BotNet.g
WebrootW32.Malware.Gen
AviraTR/Crypt.XPACK.Gen7
MAXmalware (ai score=88)
ViRobotBackdoor.Win32.A.BotNet.7168[UPX]
ZoneAlarmBackdoor.Win32.BotNet.dv
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win.HDC.R513357
VBA32Trojan.Zbot.12523
ALYacGen:Variant.Razy.158071
TACHYONBackdoor/W32.BotNet.11264
MalwarebytesMalware.Heuristic.1003
IkarusBackdoor.Win32.BotNet
RisingMalware.Zbot!8.E95E (TFE:5:ur5EjgdjJ7Q)
YandexTrojan.GenAsa!WHJr+77T2UQ
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AC.73A8A!tr
AVGWin32:Evo-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Razy.158071?

Razy.158071 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment