Malware

Razy.636403 removal instruction

Malware Removal

The Razy.636403 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.636403 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Razy.636403?


File Info:

name: 8D5F503EAE504C47A512.mlw
path: /opt/CAPEv2/storage/binaries/a4579821efa4aee8ffeb447001c62390159b1553081ead3f49381a7e5991fa3b
crc32: 196E0CD5
md5: 8d5f503eae504c47a51275c3f8fc69be
sha1: 8c3e4fcc291dfb3a4957e89ff87caff21b8178b7
sha256: a4579821efa4aee8ffeb447001c62390159b1553081ead3f49381a7e5991fa3b
sha512: 2914b92754fb617f9c936ecaf0f7d9f032dd53942bac43da85864b66fff25b3425034beba72781dbcaf658045c8db8adab03addc361ce8de53ffd7be17a84817
ssdeep: 12288:Z/hrADIxPdBpjOzyTPabxipGnUur3h1f1GRHsLqUhHJTm5jO6rD+M5tcUiM1jUcK:ZJrHP0zysYGH2CqUNlwjzSMn3VUWjG
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T12FC59D61FE0B4A81DC4180F067DF561F5F9B1F8857F12819C3A7EBBA2095BA8D32D252
sha3_384: 5f45d79e8426acc1c5692aeb2a3955201c38c28a868ac811c65b9d064f4d0fd00deabc680c0f9062c691c6c6a1622044
ep_bytes: 680a104000e8b211f9ffe828fffeffff
timestamp: 2018-04-13 13:09:45

Version Info:

0: [No Data]

Razy.636403 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Razy.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.636403
FireEyeGeneric.mg.8d5f503eae504c47
CAT-QuickHealTrojan.Sabsik
McAfeeGenericRXAA-FA!8D5F503EAE50
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 001d511d1 )
AlibabaTrojan:Win32/FakeAlert.9661cb92
K7GWTrojan ( 001d511d1 )
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderThetaGen:NN.ZexaF.34114.HsX@aeFR35
CyrenW32/FakeAlert.FY.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.RZS
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Agent.xalxao
BitDefenderGen:Variant.Razy.636403
AvastWin32:Trojan-gen
TencentWin32.Trojan.Razy.Eckt
Ad-AwareGen:Variant.Razy.636403
EmsisoftGen:Variant.Razy.636403 (B)
SophosMal/Generic-S
IkarusTrojan.Win32.Agent
GDataGen:Variant.Razy.636403
eGambitUnsafe.AI_Score_100%
AviraHEUR/AGEN.1142577
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Razy.D9B5F3
MicrosoftTrojan:Win32/Tiggre!rfn
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.FakeAlert.R228615
Acronissuspicious
ALYacGen:Variant.Razy.636403
MAXmalware (ai score=100)
MalwarebytesTrojan.Agent
TrendMicro-HouseCallTROJ_GEN.R002C0WLR21
RisingTrojan.Generic@ML.90 (RDML:KTK13t+hWPSgzPpJV3UbEQ)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.RZS!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.eae504
PandaTrj/Genetic.gen

How to remove Razy.636403?

Razy.636403 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment