Malware

Razy.780176 information

Malware Removal

The Razy.780176 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.780176 virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs

Related domains:

wpad.local-net

How to determine Razy.780176?


File Info:

name: 94C6A1634A73FBA4BB7D.mlw
path: /opt/CAPEv2/storage/binaries/72768a6b50f1c44aad6f99d80dd1dc662a0c2decae7d5004cb0d3d2c54d69f14
crc32: 7F68332E
md5: 94c6a1634a73fba4bb7dbef9c3160e84
sha1: 9bc78338ad113cc86f3c3e11230bba480f011f3e
sha256: 72768a6b50f1c44aad6f99d80dd1dc662a0c2decae7d5004cb0d3d2c54d69f14
sha512: 2e47d46b262cca19b8d264fb2bcf8ef096b5d30ff88d856d5caab126ba7f2b2af5ada7ade55bf23aa8aeb9473462c2b015ace31db34d2eb1b1e36382de9a3051
ssdeep: 768:jEi3OyETAn7py4NpMCSzgjb7RlPEe9kn54bfyEbmg0Dg5mmte1KHyEnqU4cSMm:9fn7o4NuIEqkn54eEbmgL4SyFiBm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CEE3762E360975FBD0F4867C811E7B1AF064AA53B4635C1D7182CA19CAA45F73B8732E
sha3_384: 5c522cbc9cb5b18012f031fac587a25270f8da5a4bc1f3be84da072e30e4f0c5f8b77919a9addb1338c994f8fe74b0ea
ep_bytes: ff250020400000000000000000000000
timestamp: 2020-10-25 01:31:16

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 2.0.0.0
InternalName: 词个不非答天表动年年仰不不字非方英是方动信信想式感乓年个年想.exe
LegalCopyright:
OriginalFilename: 词个不非答天表动年年仰不不字非方英是方动信信想式感乓年个年想.exe
ProductVersion: 2.0.0.0
Assembly Version: 2.0.0.0

Razy.780176 also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.780176
FireEyeGeneric.mg.94c6a1634a73fba4
ALYacGen:Variant.Razy.780176
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforBackdoor.MSIL.Bladabindi.gen
K7AntiVirusTrojan ( 0056befe1 )
AlibabaBackdoor:MSIL/Bladabindi.66b82bae
K7GWTrojan ( 0056befe1 )
Cybereasonmalicious.34a73f
CyrenW32/Trojan.HTZY-0193
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.XFA
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Ursu-7595005-0
KasperskyHEUR:Backdoor.MSIL.Bladabindi.gen
BitDefenderGen:Variant.Razy.780176
NANO-AntivirusTrojan.Win32.Bladabindi.jbssab
AvastWin32:TrojanX-gen [Trj]
Ad-AwareGen:Variant.Razy.780176
SophosMal/Generic-S
ComodoMalware@#2unhn7j0haod3
DrWebTrojan.DownLoader35.24518
ZillyaBackdoor.Bladabindi.Win32.21730
TrendMicroTROJ_GEN.R002C0GIG21
McAfee-GW-EditionRDN/Generic BackDoor
EmsisoftGen:Variant.Razy.780176 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Razy.780176
AviraTR/Kryptik.qouwp
Antiy-AVLTrojan/Generic.ASMalwS.30F9C39
ArcabitTrojan.Razy.DBE790
MicrosoftTrojan:Win32/Ymacco.AA72
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/MSILKrypt14.Exp
McAfeeRDN/Generic BackDoor
MAXmalware (ai score=84)
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.Downloader
TrendMicro-HouseCallTROJ_GEN.R002C0GIG21
TencentMsil.Backdoor.Bladabindi.Hupi
YandexTrojan.Kryptik!dfE13/sNuLI
IkarusTrojan.MSIL.Crypt
FortinetMSIL/Kryptik.NEH!tr
BitDefenderThetaGen:NN.ZemsilF.34294.im0@aKPMjDl
AVGWin32:TrojanX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureWin.MxResIcn.Heur.Gen

How to remove Razy.780176?

Razy.780176 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment