Malware

About “Razy.778593” infection

Malware Removal

The Razy.778593 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.778593 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Razy.778593?


File Info:

name: 36557A183BCB4B655403.mlw
path: /opt/CAPEv2/storage/binaries/33b7b1a7d93625aa0a77c30577ee65b9cb24f700a8b332bca60ee9de3a51d526
crc32: E9827AF4
md5: 36557a183bcb4b655403cc76c17b1e45
sha1: 9094d587b158a7879a18668d14d12817db35d231
sha256: 33b7b1a7d93625aa0a77c30577ee65b9cb24f700a8b332bca60ee9de3a51d526
sha512: ac61199c588229384931101ebe82a59565e12f1b195fc5b6a0ee7427df5f9851158bcbd0164bcedd38497f116f55a2dd07e75621e83009b911ae1ee679e8a384
ssdeep: 24576:QesI22+a/ZSC+gVue+zxa/ZSrJovBYTqT2RUOa/ZSAajJB6:POgxbV8xgClgC+
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T122E5DFCF2E5E4372CC0A527DA83F9E614130BCEC665EB2E227836DB67D15FC59606620
sha3_384: 30faab9b3a03bf73368105c6bddfac43fdec654d554307398553d80a76dd8cb3a376fa6568cf8a77c5124100c4495226
ep_bytes: 5c6d31c80c04b54f09e5bcde8bafd464
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Razy.778593 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.778593
CAT-QuickHealTrojan.Glupteba.S17234490
SkyhighBehavesLike.Win32.Generic.wh
McAfeeTrojan-FVOQ!36557A183BCB
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Razy.778593
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
K7GWTrojan ( 005a45ef1 )
Cybereasonmalicious.7b158a
ArcabitTrojan.Razy.DBE161 [many]
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.GIFY
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Razy-9823454-0
KasperskyTrojan.Win32.Copak.folb
BitDefenderGen:Variant.Razy.778593
NANO-AntivirusTrojan.Win32.Copak.jvibhg
AvastWin32:PWSX-gen [Trj]
TencentTrojan.Win32.Selfmod.ka
TACHYONTrojan/W32.Selfmod
EmsisoftGen:Variant.Razy.778593 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Siggen12.42976
ZillyaTrojan.Kryptik.Win32.3105278
SophosMal/Inject-GJ
IkarusTrojan.Win32.Glupteba
JiangminTrojan.Selfmod.azru
VaristW32/Trojan.MJSE-7842
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.Kryptik.gify
Kingsoftmalware.kb.a.889
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
MicrosoftTrojan:Win32/Glupteba.MT!MTB
ZoneAlarmTrojan.Win32.Copak.folb
GDataWin32.Trojan.PSE.15NLAT
GoogleDetected
AhnLab-V3Trojan/Win.OB.C5394211
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36680.a@Z@autBeKp
MAXmalware (ai score=87)
VBA32Trojan.Copak
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.BF57 (CLASSIC)
YandexTrojan.Selfmod!9PBVLJlnE2k
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:PWSX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Razy.778593?

Razy.778593 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment