Malware

About “Razy.576087” infection

Malware Removal

The Razy.576087 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.576087 virus can do?

  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Razy.576087?


File Info:

name: CE4794F8D9E622E70460.mlw
path: /opt/CAPEv2/storage/binaries/86c880fa3a3f3da4746cb451210e1728eba921afca7dd908021bce385d04eb19
crc32: 079CBCFC
md5: ce4794f8d9e622e70460ac8fb7d2fbcd
sha1: 1615ece1f59bdd0c5e9a9001e7313efe2ee6a2ab
sha256: 86c880fa3a3f3da4746cb451210e1728eba921afca7dd908021bce385d04eb19
sha512: d776aa95b04e04c036ce629bb1fe426ae70a9f9ed7d63909663ac1e3c5e78c4fa2d97ff811d18f7425728bd35de363c7b954d5c900ff9ee15dae3dce652e028e
ssdeep: 96:XpSJgxPJtEUIvU033WXj6qEZaxLQZaaw9H2B:XM6JGvUQ3gbEgwa59H
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T108C109C2FA9C9526F12207BE5D33830C7936BE14DD68966A71C4776FBC326504912B30
sha3_384: ba4c4eb770c2f4eaedb9a0bf5fd35fc183323c0990b792059878a199b1bf1bb8601d5481e42c041353142048c5150003
ep_bytes: 5231c0e8ffffffffc75e83ee0f05a000
timestamp: 2019-06-24 18:48:34

Version Info:

CompanyName: Ibsen Software
FileDescription: apatch stub
FileVersion: 1.11
InternalName: patch
LegalCopyright: Copyright 1999-2014 Joergen Ibsen
OriginalFilename: patch.exe
ProductName: apatch
ProductVersion: 1.11
Translation: 0x0409 0x04e4

Razy.576087 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Variant.Razy.576087
FireEyeGeneric.mg.ce4794f8d9e622e7
ALYacGen:Variant.Razy.576087
CylanceUnsafe
ZillyaTool.Patcher.Win32.28620
SangforTrojan.Win32.XPACK.Gen
Cybereasonmalicious.8d9e62
BitDefenderThetaGen:NN.ZexaF.34294.ai0@aWsuHHpi
SymantecPacked.Generic.128
ESET-NOD32a variant of Win32/HackTool.Patcher.W potentially unsafe
Paloaltogeneric.ml
BitDefenderGen:Variant.Razy.576087
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastFileRepMalware
Ad-AwareGen:Variant.Razy.576087
EmsisoftGen:Variant.Razy.576087 (B)
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.xh
SophosAPatch GenPatch (PUA)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Razy.576087
WebrootW32.Trojan.Tr.Crypt.Xpack
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=88)
Antiy-AVLTrojan/Generic.ASMalwS.2CE5204
ArcabitTrojan.Razy.D8CA57
MicrosoftTrojan:Win32/Occamy.C
CynetMalicious (score: 100)
McAfeeArtemis!CE4794F8D9E6
APEXMalicious
RisingTrojan.Generic@ML.98 (RDMK:Mzee8ygCUc5QHXO282lF8w)
YandexPUP.Patcher!Oj8Xw8MfCDE
MaxSecureTrojan.Malware.74677448.susgen
FortinetRiskware/Generic_PUA_BG
AVGFileRepMalware
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Razy.576087?

Razy.576087 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment