Malware

What is “Razy.928657”?

Malware Removal

The Razy.928657 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.928657 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Razy.928657?


File Info:

name: 2216A683C60A7D75D9F3.mlw
path: /opt/CAPEv2/storage/binaries/addbbf284c470355267957dfb3f0a852b827997eefc3380481ab24f3651435c2
crc32: 1B942164
md5: 2216a683c60a7d75d9f32bef997e4983
sha1: 96a1003640ef6be2987a16b4151108966b969e61
sha256: addbbf284c470355267957dfb3f0a852b827997eefc3380481ab24f3651435c2
sha512: 0aa00640d39a606bd01006cbf0250c32d9203ea8e399c46e48aaba14b8690309f5e1a394aed873ce54c93ee771634f900d911be2a81a06e258a748a7ce17c045
ssdeep: 24576:VAVrwX3RBoXmc9hfgVUIkMbw+MwHVq1RRCtyD2a0IZlD:OVrzXmAhfNsbw+nkfCgDpHZlD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A6159E123592D037D5A201725D28AB7991AEFD310F7165DBA3D40B2DAF385D32E32E63
sha3_384: 0a9e5b1fd64e5c029ceb1abce1cd9a5b816cbf0b5cd872e4574faddb92c9a0cb928f87f6a0386ff9536348068657461b
ep_bytes: e8ed050000e97afeffff558bec832568
timestamp: 2020-12-28 07:22:21

Version Info:

CompanyName: He Fei Yun Biao Xin Xi Ke Ji You Xian Gong Si
FileDescription: ZipperCloud
FileVersion: 1.0.0.11847
InternalName:
LegalCopyright: Copyright (C) 2020 He Fei Yun Biao Xin Xi Ke Ji You Xian Gong Si. All Rights Reserved.
OriginalFilename: updater.exe
ProductName: ZipperCloud
ProductVersion: 1.0.0.11847
Translation: 0x0804 0x04b0

Razy.928657 also known as:

BkavW32.AIDetect.malware1
LionicRiskware.Win32.Razy.1!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.928657
FireEyeGeneric.mg.2216a683c60a7d75
MalwarebytesPUP.Optional.ChinAd
ZillyaAdware.AdAnti.Win32.50
SangforSuspicious.Win32.Save.a
K7AntiVirusAdware ( 005774ba1 )
K7GWAdware ( 005774ba1 )
Cybereasonmalicious.640ef6
CyrenW32/Sality.E.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.AdAnti.C
APEXMalicious
BitDefenderGen:Variant.Razy.928657
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
TencentWin32.Trojan.Razy.Hnba
Ad-AwareGen:Variant.Razy.928657
SophosGeneric PUA JG (PUA)
F-SecureAdware.ADWARE/AdAnti.jyidx
VIPREVirus.Win32.Sality.at (v)
TrendMicroPE_SALITY.RL
McAfee-GW-EditionBehavesLike.Win32.Virus.ch
EmsisoftGen:Variant.Razy.928657 (B)
GDataGen:Variant.Razy.928657
JiangminAdware.Agent.askc
AviraADWARE/AdAnti.jyidx
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Razy.DE2B91
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34294.1q2@aCTbuzaj
ALYacGen:Variant.Razy.928657
MAXmalware (ai score=82)
VBA32BScope.Trojan.Agent
CylanceUnsafe
TrendMicro-HouseCallPE_SALITY.RL
RisingAdware.Agent!1.C404 (CLASSIC)
YandexPUA.AdAnti!kiIHZZT5Sjs
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.9KHZU3!tr.dldr
AVGWin32:Sality [Inf]
AvastWin32:Sality [Inf]

How to remove Razy.928657?

Razy.928657 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment