Malware

Razy.765303 malicious file

Malware Removal

The Razy.765303 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.765303 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs

How to determine Razy.765303?


File Info:

name: C12E25E058AD2F148AEF.mlw
path: /opt/CAPEv2/storage/binaries/2164f0e8d8978861f39edf067cb94f68829d71096383e79e7672d8b2dc25c935
crc32: E068A3B5
md5: c12e25e058ad2f148aef2bedcefa50d8
sha1: 37d374748945c455a9de9dfd9cdf6390d9d2ed41
sha256: 2164f0e8d8978861f39edf067cb94f68829d71096383e79e7672d8b2dc25c935
sha512: c8296ac7e7684175e6697de44ccfbc04a2e683815c10009832ea4aa39629c7ed6bdf22326b1dfe5cdc0d42b041a1d750b898d5d6f7da5cbb402b59139c5447c5
ssdeep: 3072:U0W2uF8qPu3pi6IPe2slbTTTToRuFMXnfdF:f02RRIPMlzTT3W
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16824BE51B7C8C891C97402315EABCE1903365E3DEE005E5F36D4BF9E39B722B492B2A5
sha3_384: 42fda09182c25f9a731a0e551393bd076feb14213a8cc40d383f366e1eeda69a1dc0fdf13151445cc36d7a3d94afc4ce
ep_bytes: ff25002040000000000000000000
timestamp: 2017-11-29 01:17:57

Version Info:

Translation: 0x0000 0x04b0
Comments: SZ1B1HX
CompanyName: S
FileDescription: SZ1B1
FileVersion: 1.8.7.1
InternalName: Y6OneTw.exe
LegalCopyright: Copyright © 3169
LegalTrademarks:
OriginalFilename: Y6OneTw.exe
ProductName: SZ1B1HX
ProductVersion: 1.8.7.1
Assembly Version: 5.8.4.7

Razy.765303 also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebAdware.WizzMonetize.1
MicroWorld-eScanGen:Variant.Razy.765303
FireEyeGeneric.mg.c12e25e058ad2f14
McAfeePUP-GKL
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.2162452
SangforAdware.Win32.EoRezo.Gen7
K7AntiVirusTrojan ( 0055ca211 )
AlibabaTrojan:MSIL/Kryptik.51e8f6e2
K7GWTrojan ( 0055ca211 )
Cybereasonmalicious.058ad2
BitDefenderThetaGen:NN.ZemsilF.34294.nm0@aa2v!Ah
CyrenW32/S-6690333a!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.LML
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.765303
NANO-AntivirusTrojan.Win32.WizzMonetize.evwkqe
SUPERAntiSpywareAdware.Tuto4PC/Variant
AvastWin32:AdwareX-gen [Adw]
TencentWin32.Trojan.Generic.Sunm
Ad-AwareGen:Variant.Razy.765303
EmsisoftGen:Variant.Razy.765303 (B)
ComodoTrojWare.MSIL.EoRezo.LML@7kn71c
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PKQ21
McAfee-GW-EditionPUP-GKL
SophosMal/Kryptik-AQ
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Razy.765303
JiangminTrojan.Generic.btrkw
MaxSecureTrojan.Malware.300983.susgen
AviraADWARE/EoRezo.Gen7
Antiy-AVLTrojan/Generic.ASMalwS.22E571B
GridinsoftRansom.Win32.Occamy.sa
ArcabitTrojan.Razy.DBAD77
MicrosoftTrojan:Win32/Occamy.C21
CynetMalicious (score: 99)
AhnLab-V3PUP/Win32.Bundler.C2272237
VBA32Adware.WizzMonetize
ALYacGen:Variant.Razy.765303
MAXmalware (ai score=99)
MalwarebytesTrojan.Injector
TrendMicro-HouseCallTROJ_GEN.R002C0PKQ21
IkarusTrojan.MSIL.Wizrem
eGambitUnsafe.AI_Score_98%
FortinetMSIL/Kryptik.KZF!tr
AVGWin32:AdwareX-gen [Adw]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Razy.765303?

Razy.765303 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment