Malware

Razy.881766 removal instruction

Malware Removal

The Razy.881766 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.881766 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Uses suspicious command line tools or Windows utilities

How to determine Razy.881766?


File Info:

name: FE31A0D0C691178DBF38.mlw
path: /opt/CAPEv2/storage/binaries/639350ff76a7665267e5d3a22b1c6e258638305b6f1296c766ac9b69ee224e6c
crc32: E1C0D2A6
md5: fe31a0d0c691178dbf38f53fbe44d0a8
sha1: 4acddcb1c4bc0c9801965894c843d2114742a5d9
sha256: 639350ff76a7665267e5d3a22b1c6e258638305b6f1296c766ac9b69ee224e6c
sha512: c0583f78d3cb05686cd803f1d99b5ec22915a5ef210b757c518fa6ba6b0c032ce8654e7f93bd20da3db39d2ff897f799e5ed9886de1316ee5d274fe7fd0689c5
ssdeep: 24576:JbH/93z+RAqxtMfcc7Rd0lB6Cn2uJ5TKIOYWNn0fJ2:D6Yf+IwKVN0fJ2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T124254A28A2D39061C173353295AD37B5E6BEED3504BE7A0B4760D5362E30412E73AF6E
sha3_384: 497d95e2092fec6ed62b8f9c93e79e49adac11e15cbeac3a559c056d13bf0d58e3a5fa2aa1d8afb38e4b2722c84d5e91
ep_bytes: e82e040000e94efdffff8bff558bec81
timestamp: 2011-04-21 08:54:46

Version Info:

0: [No Data]

Razy.881766 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.881766
ALYacGen:Variant.Razy.881766
CylanceUnsafe
BitDefenderGen:Variant.Razy.881766
Cybereasonmalicious.0c6911
VirITTrojan.Win32.Generic.TRX
CyrenW32/FakeAlert.FY.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
APEXMalicious
NANO-AntivirusTrojan.Win32.Inject1.djijyf
RisingTrojan.Win32.Yalrevo.aa (RDMK:cmRtazo7UE8m7Gy8BS1ATLfJFhJ8)
Ad-AwareGen:Variant.Razy.881766
SophosGeneric ML PUA (PUA)
F-SecureTrojan.TR/ATRAPS.Gen
DrWebTrojan.Inject1.1494
McAfee-GW-EditionBehavesLike.Win32.Backdoor.th
FireEyeGeneric.mg.fe31a0d0c691178d
EmsisoftGen:Variant.Razy.881766 (B)
IkarusTrojan-PWS.Win32.Eruwbi
AviraTR/ATRAPS.Gen
MAXmalware (ai score=89)
Antiy-AVLTrojan/Generic.ASMalwS.8461C7
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Razy.881766
CynetMalicious (score: 100)
VBA32BScope.Trojan.Tiggre
YandexTrojan.GenAsa!zeP7kTlc418
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.139013372.susgen
FortinetW32/Generic.AP.2957AC!tr
BitDefenderThetaAI:Packer.4AF567F91E
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Razy.881766?

Razy.881766 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment