Malware

How to remove “Razy.778691 (B)”?

Malware Removal

The Razy.778691 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.778691 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Collects information to fingerprint the system

How to determine Razy.778691 (B)?


File Info:

name: B23BD74918297D7DF375.mlw
path: /opt/CAPEv2/storage/binaries/6c0ee70433a08c4eac86344ebcc4d955296286902b54bd8de2a92c39883b5898
crc32: C32BD403
md5: b23bd74918297d7df37597412e5ed40b
sha1: 0aea216cb468b75107d7885b42752ddfebab67a6
sha256: 6c0ee70433a08c4eac86344ebcc4d955296286902b54bd8de2a92c39883b5898
sha512: 63110a13fd8e83a0087223f590e11c6b7b191d5f4037228d86b6bf714fe8b706c361076cc89c028c7cc7ab2c870da0dd40a85863e1ce893221fdfca70b41da45
ssdeep: 3072:v9s9UjrL5vSfm/ceGnpQyqPkLOpM95Fa2jhjiOC5prhYPTDlnu:vaUTxSfmvGWjCN1iOYhElu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D8348BF08580643AD88482F15C52AD3A8E1DEC615BA4ADEB1259FDD63FB31C087EE51F
sha3_384: 63d91695293585c587d5ec6ed820e55061ad9db9fd98e41b103d88bef1ed9caa394f0f5268fb97f5609480211ed530a1
ep_bytes: 558bec5155c745fc3bdb0000c745fc3b
timestamp: 2013-03-22 18:17:11

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft DirectPlay Voice Test
FileVersion: 5.03.2600.5512 (xpsp.080413-0845)
InternalName: dpvsetup.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: dpvsetup.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 5.03.2600.5512
Translation: 0x0409 0x04b0

Razy.778691 (B) also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.lIZi
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Razy.778691
ClamAVWin.Trojan.Shipup-4
FireEyeGeneric.mg.b23bd74918297d7d
CAT-QuickHealTrojanDropper.Gepys.A
ALYacGen:Variant.Razy.778691
MalwarebytesTrojan.FakeMS.ED
ZillyaTrojan.ShipUp.Win32.1167
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.918297
BaiduWin32.Trojan.Agent.eq
VirITTrojan.Win32.Generic.QGQ
CyrenW32/Zbot.JC.gen!Eldorado
SymantecPacked.Generic.459
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.AXID
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.ShipUp.boo
BitDefenderGen:Variant.Razy.778691
NANO-AntivirusTrojan.Win32.ShipUp.bqolrw
AvastWin32:Gepys-J [Trj]
TencentMalware.Win32.Gencirc.10b4460d
Ad-AwareGen:Variant.Razy.778691
TACHYONTrojan/W32.ShipUp.249600
EmsisoftGen:Variant.Razy.778691 (B)
ComodoTrojWare.Win32.Kryptik.AYQE@4wlbfl
DrWebTrojan.Siggen5.1870
VIPREGen:Variant.Razy.778691
TrendMicroTROJ_KRYPTK.SML3
McAfee-GW-EditionPacked-AM!B23BD7491829
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/EncPk-AIT
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1KR2NFM
JiangminTrojan/ShipUp.aai
WebrootW32.Malware.Gen
AviraTR/Crypt.ZPACK.Gen8
Antiy-AVLTrojan/Generic.ASMalwS.217
ArcabitTrojan.Razy.DBE1C3
MicrosoftTrojan:Win32/ShipUp.DSK!MTB
GoogleDetected
AhnLab-V3Trojan/Win32.Shipup.R58811
Acronissuspicious
McAfeePacked-AM!B23BD7491829
MAXmalware (ai score=86)
VBA32BScope.Malware-Cryptor.Hlux
CylanceUnsafe
TrendMicro-HouseCallTROJ_KRYPTK.SML3
RisingTrojan.Kryptik!1.AB8B (CLASSIC)
YandexTrojan.GenAsa!inOEU/QgBGA
IkarusTrojan.Win32.ShipUp
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.AYUW!tr
BitDefenderThetaGen:NN.ZexaF.34646.py1@aazg2cei
AVGWin32:Gepys-J [Trj]
PandaTrj/Hexas.HEU
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Razy.778691 (B)?

Razy.778691 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment