Malware

About “Razy.778593” infection

Malware Removal

The Razy.778593 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.778593 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family

How to determine Razy.778593?


File Info:

name: E0C05E8515F56AF70DC8.mlw
path: /opt/CAPEv2/storage/binaries/ded20ec011ebf0024ac18bf77ddf467f806b2d47afb0677e4fe49cabf058f004
crc32: F90823CB
md5: e0c05e8515f56af70dc80b7ab3388766
sha1: b5df8ce67a0e2d4e5331b0c648b4305876055bc8
sha256: ded20ec011ebf0024ac18bf77ddf467f806b2d47afb0677e4fe49cabf058f004
sha512: 20ecf6d61217141a03003df3becb3633050717c29f3eef99a3853d200aa6bebbcf2112d99936d15a81e94bcb375b6fc53f08c8d44900c3fbb0c6b4ff2bcb6c02
ssdeep: 12288:sRFh+zlpFUteiSXuTVI6JEkPz5HNvydIDdNbGjtxK9r+F3LGKTygwGjlDa/ZS:W4tcr+Fdw0a/ZS
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T136154A9D27A2D797C046A6756A3ECA20471C38B87B37D2223048F68B79ED3D365436F4
sha3_384: bf3e68f29d875fb8879fd9fdbd8ab2f09b896f51db91aa827c76d33f33bdb1c61820d102181fd3c54809aced94ebbdfe
ep_bytes: 578b130907e2978e02039e1f8049f6a5
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Razy.778593 also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Razy.778593
CAT-QuickHealTrojan.Glupteba.S17234490
SkyhighBehavesLike.Win32.PWSZbot.cm
McAfeeTrojan-FVOQ!E0C05E8515F5
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Razy.778593
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
K7GWTrojan ( 005363ff1 )
ArcabitTrojan.Razy.DBE161
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.GIFY
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Dridex-9860931-1
KasperskyVHO:Trojan.Win32.Bingoml.gen
BitDefenderGen:Variant.Razy.778593
NANO-AntivirusTrojan.Win32.Kryptik.fgvqyh
AvastWin32:PWSX-gen [Trj]
TencentTrojan.Win32.Selfmod.ka
EmsisoftGen:Variant.Razy.778593 (B)
F-SecureHeuristic.HEUR/AGEN.1344450
DrWebTrojan.Siggen12.42976
ZillyaTrojan.Kryptik.Win32.1485233
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.e0c05e8515f56af7
SophosMal/Inject-GJ
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.cuzcy
VaristW32/Zusy.EM.gen!Eldorado
AviraHEUR/AGEN.1344450
MAXmalware (ai score=82)
Antiy-AVLTrojan/Win32.Kryptik.gify
Kingsoftmalware.kb.a.991
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
MicrosoftTrojan:Win32/Glupteba.MT!MTB
ZoneAlarmVHO:Trojan.Win32.Bingoml.gen
GDataWin32.Trojan.PSE.11XGYE9
GoogleDetected
AhnLab-V3Trojan/Win32.Packed.R357221
Acronissuspicious
VBA32Trojan.Copak
ALYacGen:Variant.Razy.778593
TACHYONTrojan/W32.Selfmod
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B34D (CLASSIC)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GIFQ!tr
BitDefenderThetaGen:NN.ZexaF.36744.3GW@a8lvKEl
AVGWin32:PWSX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Razy.778593?

Razy.778593 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment