Malware

Razy.736153 (file analysis)

Malware Removal

The Razy.736153 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.736153 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Afrikaans
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Detects Sandboxie through the presence of a library
  • Installs itself for autorun at Windows startup
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Creates a copy of itself

How to determine Razy.736153?


File Info:

crc32: B05B7DBE
md5: 7bf05df7114ec583e68c7e9b5d72c126
name: 7BF05DF7114EC583E68C7E9B5D72C126.mlw
sha1: aaeaeadf97112ee00ea7ea63d08d7c5bf60b6e5d
sha256: c339ae98afdb0a99ae4655c2161b206ce0d854f9c8d1ab7996b7549ee3bdcc54
sha512: f389e00ba6428c9586db2ce71b33855170f59f26ea4519fae7a492fe02f5919a004795f2b329962273ef87b6c8c686293c18e691833550798b0d5a2b0accd69e
ssdeep: 768:kLhtG9QnDDLpT2XZBzzEhoeyAwse+NGu0AwfraQ7:kLhtG9+sHEho8wMVwrl7
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

ProductName: Plays Oath Pivot Limps
FileDescription: Alex
OriginalFilename: Logo.exe
CompanyName: Ivobi
Translation: 0x0409 0x04b0

Razy.736153 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebBackDoor.Andromeda.22
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.736153
CylanceUnsafe
ZillyaBackdoor.Androm.Win32.625
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.7114ec
SymantecW32.Cridex!gen1
ESET-NOD32a variant of Win32/Kryptik.AUHL
APEXMalicious
AvastWin32:Malware-gen
KasperskyBackdoor.Win32.Androm.ouai
BitDefenderGen:Variant.Razy.736153
NANO-AntivirusTrojan.Win32.Andromeda.cugagn
MicroWorld-eScanGen:Variant.Razy.736153
TencentWin32.Backdoor.Androm.Ammi
Ad-AwareGen:Variant.Razy.736153
SophosML/PE-A + Mal/Zbot-LB
ComodoMalware@#45687s6cf0np
BitDefenderThetaGen:NN.ZexaF.34058.cmKfaGChx4mG
VIPRETrojan.Win32.Zbocheman.fb (v)
McAfee-GW-EditionBehavesLike.Win32.Generic.pc
FireEyeGeneric.mg.7bf05df7114ec583
EmsisoftGen:Variant.Razy.736153 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.ZPACK.Gen6
Antiy-AVLTrojan/Generic.ASMalwS.7E7E08
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmBackdoor.Win32.Androm.ouai
GDataGen:Variant.Razy.736153
McAfeeArtemis!7BF05DF7114E
MAXmalware (ai score=83)
VBA32BScope.Trojan.KillAV
PandaBck/Qbot.AO
YandexBackDoor.Andromeda!T+4A3OqF95U
IkarusP2P-Worm.Win32.Palevo
FortinetW32/Yakes.B!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Generic/Trojan.Generic.HgAASUUA

How to remove Razy.736153?

Razy.736153 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment