Malware

Razy.835764 removal guide

Malware Removal

The Razy.835764 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.835764 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Razy.835764?


File Info:

name: FB1C1CEDD2A6A2EF3AA0.mlw
path: /opt/CAPEv2/storage/binaries/a3cee5ff3412a2e135405f2f3766c969d249497fd91555063dfe8042bf04c01c
crc32: BA487527
md5: fb1c1cedd2a6a2ef3aa020091879bf63
sha1: 43c5bccaff055154498c61fbc74acf89cdc9dc81
sha256: a3cee5ff3412a2e135405f2f3766c969d249497fd91555063dfe8042bf04c01c
sha512: 75a7f684f483d1ff92c2a28f16c58181fc2f6548c00e6cdb67ec714d9c180dca974dbf4f633563e7ba7d988d268ac4edbc9ce07d5dede37dfc41d00e08ff1058
ssdeep: 49152:YTUO92imDta4tpCwTUO92imDta4FWSytLoqUkpCwTUF:BO3CbCZO3C1stsFMCZF
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1F0C5AF23BB90D0B7C573023189A5A2B0BABDFDB047219A4F6754DF192E716916F3A307
sha3_384: 77da405021e778b92d89676966a00d73d84fce96e98f398dbde212b839f22089cb7595249fd863f9a3967cb38f221b66
ep_bytes: ff51488b45e86a05508b08ff91940000
timestamp: 2020-03-03 21:00:45

Version Info:

0: [No Data]

Razy.835764 also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.fb1c1cedd2a6a2ef
ALYacGen:Variant.Razy.835764
ClamAVWin.Malware.Filerepmalware-9883702-0
AvastWin32:Malware-gen
DrWebTrojan.DownLoader36.39534
McAfee-GW-EditionArtemis!Trojan
Antiy-AVLTrojan/Generic.ASBOL.C6A7
MicrosoftTrojan:Win32/Wacatac.B!ml
McAfeeArtemis!FB1C1CEDD2A6
RisingTrojan.Fsysna!1.D1F1 (CLASSIC)
SentinelOneStatic AI – Suspicious PE
FortinetW32/DownLoader36.593B!tr
AVGWin32:Malware-gen

How to remove Razy.835764?

Razy.835764 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment