Malware

About “Razy.525078” infection

Malware Removal

The Razy.525078 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.525078 virus can do?

  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Polish
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Razy.525078?


File Info:

name: 363D928537BBEB3BFDE5.mlw
path: /opt/CAPEv2/storage/binaries/e854f39ef444a87bc86d56ca99a37d969fb631007529e6c8899ee0d30a3cc210
crc32: 08641C17
md5: 363d928537bbeb3bfde53321786d32bb
sha1: b936662eb4e7143993cc96892331acc1f3a37527
sha256: e854f39ef444a87bc86d56ca99a37d969fb631007529e6c8899ee0d30a3cc210
sha512: e3a2084e1fed8d2f464a3e6267ce76bacbfc46085a3e77bc25710602f904ebc74f9df411add3a770a0454d8582fd9a8f067e1136ce40cfe190d195f6753f6ada
ssdeep: 384:5N3x7mMBkVtyh20Rq/AeSpJyvzZlLt0VGNZrjWiZQY1V+UptMZJ+mfj2l64dgYb:5MqUgzyv9R+oZQyVLtMZMOw6A
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FF134A086AF1CC23E42920340BA189919F7EED9029A55E87BD047F5E7DB2243CDF279D
sha3_384: 67ab45c67f41071994efa1a8d311f05dd6f6181afd13dc87e283c4656e25716fbabbd3a1f80ee8381a3ea0fd4ea6b831
ep_bytes: b872374000e8330000009368e9124000
timestamp: 1987-09-12 12:47:02

Version Info:

0: [No Data]

Razy.525078 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.525078
FireEyeGeneric.mg.363d928537bbeb3b
McAfeeArtemis!363D928537BB
CylanceUnsafe
SangforRiskware.Win32.Agent.ky
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/Tiggre.6dffc85f
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.537bbe
SymantecML.Attribute.HighConfidence
Paloaltogeneric.ml
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Razy.525078
NANO-AntivirusTrojan.Win32.Crypted.dhafbl
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.116933e8
EmsisoftGen:Variant.Razy.525078 (B)
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.pt
SentinelOneStatic AI – Malicious PE
SophosMal/Generic-R + Mal/ZboCheMan-I
APEXMalicious
GDataGen:Variant.Razy.525078
MaxSecureTrojan.Malware.1728101.susgen
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.1815368
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Tiggre!rfn
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.525078
MAXmalware (ai score=100)
VBA32BScope.Trojan.Wacatac
RisingTrojan.Generic@ML.91 (RDML:ao0OHYrwsOy+AVc58lM/ag)
IkarusTrojan.Crypt
eGambitGeneric.Malware
WebrootW32.Malware.Heur.Dkvt
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Razy.525078?

Razy.525078 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment