Malware

What is “Razy.377872”?

Malware Removal

The Razy.377872 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.377872 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system

How to determine Razy.377872?


File Info:

crc32: D1E07122
md5: f0ba35a654297b135effb331a9ede255
name: F0BA35A654297B135EFFB331A9EDE255.mlw
sha1: 84caf6925e796da1a7d42a1ff2c001bbba251351
sha256: 7a3ff91b1cf1b5f319c04141c70cec23f1b1f15014effbc68da2d0f3b6f2ad6e
sha512: 6e5062b43ebbe77f719075e57db52a5fd945922d3dbfa25488703aef82d0f686391716575e2d8c1d2e8c750aa214f780e1e73733eb07c6e7d9e2816115b8f405
ssdeep: 6144:Ky49gqEmVp3VZPYZ41gWAOJl0Ei0MBIG:Ky49VxBWAZXJiOG
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: sgfnghmj.exe

Razy.377872 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.377872
FireEyeGeneric.mg.f0ba35a654297b13
McAfeePacked-FKN!F0BA35A65429
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Coins.i!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0053d5971 )
BitDefenderGen:Variant.Razy.377872
K7GWTrojan ( 0053d5971 )
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/GandCrypt.F.gen!Eldorado
SymantecPacked.Generic.525
APEXMalicious
AvastFileRepMalware
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojanPSW:Win32/GandCrab.c4430e1f
NANO-AntivirusTrojan.Win32.Coins.fhokjc
RisingMalware.Obscure/Heur!1.9E03 (CLOUD)
Ad-AwareGen:Variant.Razy.377872
EmsisoftGen:Variant.Razy.377872 (B)
ComodoTrojWare.Win32.Ransom.Gandcrab.GJ@7tcda3
F-SecureHeuristic.HEUR/AGEN.1103434
ZillyaTrojan.GenericKD.Win32.153355
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
SophosMal/Generic-S + Mal/GandCrab-B
IkarusTrojan.Win32.Krypt
AviraHEUR/AGEN.1103434
Antiy-AVLTrojan[PSW]/Win32.Coins
MicrosoftTrojan:Win32/Skeeyah.A!rfn
ArcabitTrojan.Razy.D5C410
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AhnLab-V3Win-Trojan/Gandcrab07.Exp
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Razy.377872
ESET-NOD32Win32/PSW.Delf.OSF
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34608.pu0@aa2UYcaG
ALYacGen:Variant.Razy.377872
VBA32BScope.Trojan.Fuerboos
MalwarebytesTrojan.Agent
PandaTrj/GdSda.A
TencentWin32.Trojan-qqpass.Qqrob.Ecjy
YandexTrojan.GenAsa!SQbTHyNElNM
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GJUV!tr.ransom
AVGFileRepMalware
Cybereasonmalicious.654297
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HwoCucMA

How to remove Razy.377872?

Razy.377872 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment