Malware

How to remove “Razy.865777”?

Malware Removal

The Razy.865777 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.865777 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Unconventionial language used in binary resources: Arabic (Egypt)
  • Authenticode signature is invalid

How to determine Razy.865777?


File Info:

name: 55B988972618173E7156.mlw
path: /opt/CAPEv2/storage/binaries/767109ac76debdedd223d593bcfec7439dd3880ffa427651012f3acd31372f4e
crc32: BF8A0FD8
md5: 55b988972618173e71568cd85787a667
sha1: 52c0ac7fd59f8cf6f6a0dd13900330f1779a7bc1
sha256: 767109ac76debdedd223d593bcfec7439dd3880ffa427651012f3acd31372f4e
sha512: 0478f0bb914c4fa926d62c13bd47fb7b3b87bf2c822e2f8bdd286eac7da6a35adcfbb2a0eae523e62540a1af9db4e9222a941cfa6ee5180df8a9876e66369e2b
ssdeep: 384:NZtJbbOfVq5CXLMQWxbMQ1FgT2350HxiFNs6Qpl:NZPG9v5WhGW5hWJpl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12DB548725AA0A822F9E3543790C50810639ABE65F07C7D867F9872C51BB41E65FCC2FE
sha3_384: cc076c3d0b92c42a5ca684bf27c696f08d510ac66d64deb47c717883e5b07f02b1538e969c50b5dcdc48e39e9f3200fd
ep_bytes: 5589e581ecc4020000b9c50e98f38bd1
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Razy.865777 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Waldek.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.865777
FireEyeGeneric.mg.55b988972618173e
McAfeeArtemis!55B988972618
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaTrojan:Win32/Waldek.7c87e7b0
K7GWTrojan ( 00537f0d1 )
K7AntiVirusTrojan ( 00537f0d1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GIWA
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Waldek.vho
BitDefenderGen:Variant.Razy.865777
TencentWin32.Trojan.Waldek.Swuz
SophosMal/Generic-S
McAfee-GW-EditionArtemis!Trojan
EmsisoftGen:Variant.Razy.865777 (B)
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.32ACD9C
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Razy.865777
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4447753
BitDefenderThetaGen:NN.ZexaF.34182.qwW@aeRGm2gG
ALYacGen:Variant.Razy.865777
MAXmalware (ai score=89)
VBA32BScope.Trojan.Waldek
RisingDownloader.Small!8.B41 (CLOUD)
SentinelOneStatic AI – Suspicious PE
FortinetW32/Kryptik.GIWA!tr
AVGWin32:MalwareX-gen [Trj]
PandaTrj/CI.A

How to remove Razy.865777?

Razy.865777 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment