Malware

Razy.64130 (file analysis)

Malware Removal

The Razy.64130 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.64130 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.

How to determine Razy.64130?


File Info:

crc32: 7E20887F
md5: bbd2777c4277a21ff576f4bfe85edc33
name: BBD2777C4277A21FF576F4BFE85EDC33.mlw
sha1: aad0a0d97e9d52b8331858e0d7992d6239b832e6
sha256: 977cd007604d1c40b3d9cc301305c73cf156f0e8e2398d0b6deac74abbac334d
sha512: 42b6016a213fc98ade477b9a32513076a21742631be7fa94d0b67c9193f9ed67cae56d9bdb9ac5657e121a873eb6736c012b200c54f12d843ca217801650aaa2
ssdeep: 3072:9BDVT9fbYV6jCFAq9IjWw7fU3OwORjPgi6jfI5nHUS+MuR9jaz2/:9VVT9fbYV6OFA0IxkNORMiZnHNk9ja
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Mesomitosis Tyees
InternalName: ewftes
FileVersion: 7.3
CompanyName: Mesomitosis Tyees
ProductName: ewftes quileces
ProductVersion: 7.3
FileDescription: ewftes beiruti sho
OriginalFilename: ewftes.exe
Translation: 0x0409 0x04b0

Razy.64130 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 00520cc21 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4691
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.64130
CylanceUnsafe
ZillyaTrojan.Zerber.Win32.4921
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Zerber.3200e614
K7GWTrojan ( 00520cc21 )
Cybereasonmalicious.c4277a
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.HHYVOJV
APEXMalicious
AvastFileRepMalware
KasperskyTrojan-Ransom.Win32.Zerber.fivb
BitDefenderGen:Variant.Razy.64130
NANO-AntivirusTrojan.Win32.Zerber.evomuk
MicroWorld-eScanGen:Variant.Razy.64130
TencentWin32.Trojan.Zerber.Pjne
Ad-AwareGen:Variant.Razy.64130
SophosMal/Generic-S
ComodoMalCrypt.Indus!@1qrzi1
BitDefenderThetaGen:NN.ZexaF.34628.hu0@aKj6pLji
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CERBER.F117KU
McAfee-GW-EditionRansomware-GIX!BBD2777C4277
FireEyeGeneric.mg.bbd2777c4277a21f
EmsisoftGen:Variant.Razy.64130 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Zerber.ekt
AviraTR/Agent.hifti
MicrosoftRansom:Win32/Cerber
ArcabitTrojan.Razy.DFA82
AegisLabTrojan.Multi.Generic.4!c
GDataGen:Variant.Razy.64130
AhnLab-V3Win-Trojan/Emotet2.Exp
McAfeeRansomware-GIX!BBD2777C4277
MAXmalware (ai score=99)
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_CERBER.F117KU
RisingTrojan.Kryptik!8.8 (CLOUD)
IkarusTrojan.SuspectCRC
FortinetW32/Kryptik.EYKI!tr
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Cerber.HxQBErsA

How to remove Razy.64130?

Razy.64130 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment