Malware

Should I remove “Razy.778593”?

Malware Removal

The Razy.778593 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.778593 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Creates a copy of itself
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Razy.778593?


File Info:

name: 68E49E73C01394760360.mlw
path: /opt/CAPEv2/storage/binaries/07aa8bbec505ebac7b26b220867e5be19ac1fea1e4c78363042d056fa768ff1a
crc32: 6EE33221
md5: 68e49e73c0139476036069a167d91392
sha1: 70c0a508081e9c51e9bb466049764638e2875b27
sha256: 07aa8bbec505ebac7b26b220867e5be19ac1fea1e4c78363042d056fa768ff1a
sha512: afcded69f89ed9b183af585d96ebab5068def696a6e18165f1f154e8262eb26c54917a77ee7c9e28955db2c81add6d9ed84dbe20310601e3e268ddc02001334e
ssdeep: 24576:DYH41ViRHeAiyAgja/ZSC+gVue+zxa/ZSrJovBYTqT2RUOa/ZSAajJBMqAX1Ea/B:wcVQjgxbV8xgClgCo/ugD8xgClg9
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T16156250B2E5D8BB2CC8B627D683F8DE1C501ACAD661AB2F9234B65727D60FC1E505770
sha3_384: bf9ce8a8991ea62038b900ea8ed731ba62a12e57f43a5200b0bbfcf0607af21d427520055e3254b861e656c1edd1b9f5
ep_bytes: f1a50424a1cc80a3a42d89322667e188
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Razy.778593 also known as:

BkavW32.AIDetectMalware
ClamAVWin.Packed.Razy-9823454-0
CAT-QuickHealTrojan.Glupteba.S17234490
SkyhighBehavesLike.Win32.Generic.th
ALYacGen:Variant.Razy.778593
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Kryptik.Win32.3105278
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
K7GWTrojan ( 0001b3411 )
Cybereasonmalicious.8081e9
BitDefenderThetaGen:NN.ZexaF.36744.@@Z@autBeKp
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.GIFY
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Copak.folb
BitDefenderGen:Variant.Razy.778593
NANO-AntivirusTrojan.Win32.Selfmod.ixgbep
MicroWorld-eScanGen:Variant.Razy.778593
RisingTrojan.Kryptik!1.BF57 (CLASSIC)
EmsisoftGen:Variant.Razy.778593 (B)
F-SecureTrojan.TR/Dropper.Gen
VIPREGen:Variant.Razy.778593
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.68e49e73c0139476
SophosMal/Inject-GJ
IkarusTrojan.Win32.Glupteba
JiangminTrojan.Generic.gsvhm
VaristW32/Trojan.MJSE-7842
AviraTR/Dropper.Gen
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.Kryptik.gify
MicrosoftTrojan:Win32/Glupteba.MT!MTB
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
ArcabitTrojan.Razy.DBE161 [many]
ZoneAlarmTrojan.Win32.Copak.folb
GDataWin32.Trojan.PSE.15NLAT
GoogleDetected
AhnLab-V3Trojan/Win.OB.C5394211
Acronissuspicious
McAfeeTrojan-FVOQ!68E49E73C013
TACHYONTrojan/W32.Selfmod
DeepInstinctMALICIOUS
VBA32Trojan.Copak
Cylanceunsafe
PandaTrj/Genetic.gen
TencentTrojan.Win32.Selfmod.ka
YandexTrojan.Selfmod!9PBVLJlnE2k
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]

How to remove Razy.778593?

Razy.778593 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment