Malware

Razy.846780 removal instruction

Malware Removal

The Razy.846780 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.846780 virus can do?

  • Presents an Authenticode digital signature
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Razy.846780?


File Info:

name: 052CCE32B2B520C6B3E1.mlw
path: /opt/CAPEv2/storage/binaries/282e1e6a4299f7a8f1bda615e063142befd0a90cc2af780b928239aeadd2a37b
crc32: DBC67B0A
md5: 052cce32b2b520c6b3e11905c984e91c
sha1: aafd481cb8d0901face3fd0bb7973d570f0a5228
sha256: 282e1e6a4299f7a8f1bda615e063142befd0a90cc2af780b928239aeadd2a37b
sha512: 315b0797f308277cb144eadbc921c1a42c05e21c8d228ba328d74f0a4f6468f29225ef436878b384070d48c6fe2a75ffbe004f6f13b5f98f50a308050afef565
ssdeep: 24576:2bjdondScVw6hNNpH05r8oqxufxiiltCGG:0ondSqk53+G
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B8457D353F18DB10C165693BC9DB414887FC9C1227A6FA76348A33EDC565BA7AD0A0CE
sha3_384: 02a8e0e013f450ecd1e93544fe87e3030291fce0692a3fba7d1472a25a9c71a97136ffa8ae843e398a5a56ae22f1fa27
ep_bytes: ff250020400000000000000000000000
timestamp: 2010-12-24 08:25:48

Version Info:

Translation: 0x0000 0x04b0
Comments: Germany Launcher sfx
CompanyName: Google from Europe
FileDescription: BelkaNews for Germany
FileVersion: 5.64.7.51
InternalName: setup.exe
LegalCopyright: Copyright © 1994-2021 Firmined Europe
OriginalFilename: setup.exe
ProductName: Google Developers
ProductVersion: 5.64.7.51
Assembly Version: 1.0.0.0

Razy.846780 also known as:

LionicTrojan.MSIL.Agent.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.846780
FireEyeGeneric.mg.052cce32b2b520c6
ALYacGen:Variant.Razy.846780
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Wacatac.B
K7AntiVirusTrojan ( 005785351 )
AlibabaBackdoor:MSIL/Kryptik.a429d106
K7GWTrojan ( 005785351 )
Cybereasonmalicious.2b2b52
CyrenW32/Trojan.BHBX-5147
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/Kryptik.ZUW
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Backdoor.MSIL.Agent.gen
BitDefenderGen:Variant.Razy.846780
NANO-AntivirusTrojan.Win32.GenCBL.indodg
AvastWin32:Trojan-gen
TencentWin32.Trojan.Falsesign.Crk
Ad-AwareGen:Variant.Razy.846780
EmsisoftTrojan.Crypt (A)
DrWebTrojan.PWS.Siggen2.61882
ZillyaTrojan.Kryptik.Win32.3582134
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
IkarusTrojan.Win32.Generic
GDataGen:Variant.Razy.846780
JiangminBackdoor.MSIL.ejoh
AviraHEUR/AGEN.1208388
Antiy-AVLTrojan/Generic.ASMalwS.3184850
MicrosoftTrojanSpy:Win32/Aicat.A!ml
AhnLab-V3PUP/Win32.RL_Generic.C4349710
McAfeeArtemis!052CCE32B2B5
MAXmalware (ai score=83)
MalwarebytesSpyware.RedLineStealer
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:0RCacfj+5Ktqjxy01JU0Cw)
YandexTrojan.GenCBL!Bt0pC7rSkdM
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.11035479.susgen
FortinetW32/GenCBL.ZY!tr
BitDefenderThetaGen:NN.ZemsilF.34212.ir1@aixMzo
AVGWin32:Trojan-gen
PandaTrj/GdSda.A

How to remove Razy.846780?

Razy.846780 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment