Malware

About “Razy.653768” infection

Malware Removal

The Razy.653768 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.653768 virus can do?

  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Network activity detected but not expressed in API logs
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Razy.653768?


File Info:

crc32: F7BB9652
md5: b1aa02c755cf711ac0f96a49c1005f12
name: B1AA02C755CF711AC0F96A49C1005F12.mlw
sha1: 2bc2f2363c6a2ab8ec8f9b9bd83f4edd5d9e3430
sha256: e3002e3e00beb64ffb34ae5ba4ac62eddeea234d6f7595663e08b4e855e2e0c9
sha512: 6a4219b6dfb9563e523641045087daa44cbad91bb4998c0edb86ba071a3988382f754951756e35687d2bf4b927206dc3c71808b6c7d22ac3038e3b8b471a3806
ssdeep: 6144:UKQIxlYWOBDr7/kinlC2UgZ8lxbL/UzfZD6f7KVCGipSChT:rQIjqHznlC2UgZWxbLczfZDGK8djp
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

LegalCopyright: (C) Techsoft
InternalName: setup
FileVersion: 1,0,0,0
CompanyName: Techsoft
LegalTrademarks: (C) Techsoft
ProductName: Installer
ProductVersion: 1,0,0,0
FileDescription: Installer
OriginalFilename: setup.exe
Translation: 0x0409 0x04e4

Razy.653768 also known as:

K7AntiVirusTrojan ( 004ccea91 )
LionicTrojan.Win32.Generic.4!c
DrWebTrojan.Encoder.1479
CynetMalicious (score: 99)
ALYacGen:Variant.Razy.653768
CylanceUnsafe
ZillyaBackdoor.PePatch.Win32.100646
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojan:Win32/Filecoder.a511ce32
K7GWTrojan ( 004ccea91 )
Cybereasonmalicious.755cf7
SymantecRansom.EncRaaS!g1
APEXMalicious
AvastWin32:Malware-gen
BitDefenderGen:Variant.Razy.653768
NANO-AntivirusTrojan.Win32.Encoder.ebfvrx
MicroWorld-eScanGen:Variant.Razy.653768
Ad-AwareGen:Variant.Razy.653768
BitDefenderThetaGen:NN.ZexaF.34110.yG0@ayvVnwbi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CRYPRAAS.SMA
McAfee-GW-EditionBehavesLike.Win32.BadFile.fh
FireEyeGeneric.mg.b1aa02c755cf711a
EmsisoftGen:Variant.Razy.653768 (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/Taranis.2819
KingsoftWin32.Troj.Undef.(kcloud)
GDataGen:Variant.Razy.653768
AhnLab-V3Trojan/Win32.Ransom.R199891
McAfeeArtemis!B1AA02C755CF
MAXmalware (ai score=82)
VBA32Trojan.Encoder
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_CRYPRAAS.SMA
TencentMalware.Win32.Gencirc.10c2ba86
YandexTrojan.GenAsa!cfegrW0EC8o
IkarusTrojan.SuspectCRC
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Razy.653768?

Razy.653768 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment