Malware

What is “Razy.975292”?

Malware Removal

The Razy.975292 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.975292 virus can do?

  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Razy.975292?


File Info:

name: 01264CA70E18ACEA0F71.mlw
path: /opt/CAPEv2/storage/binaries/5257ac6bf4f477ed5eaa257f5cab12b0870d417cbd3d6c294c458d0bc0b7a38d
crc32: DF06DC2B
md5: 01264ca70e18acea0f7133c8dbc9d687
sha1: 3ec99787c5195edf1d7a489ab1ec924e93822674
sha256: 5257ac6bf4f477ed5eaa257f5cab12b0870d417cbd3d6c294c458d0bc0b7a38d
sha512: 91372650f272b512fc6a5130f156c3b602a62840c25e365f7a236aac34cd8d590e14913f93d3aaebfc1891090fa0a860c701540f070083b1f1e3a55370247eb6
ssdeep: 196608:tEAPle9sM3l0v1AuaFSD3mS80qwCtYh5wZjzEl4Ws8/XMeSpz4/Kbe:tNPgiMNfFSD2OvCtYh58KcJpz4SC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D3C623943E40156FF83CA1B8E527869DE25CFD71E532ECD0DEC90ABBD4AB5004B62939
sha3_384: 6f6bf342827e23a1480f9c117b53a6a962a78bf2778d854ca2e480aadfde67384d550b9c0799aca67446c2dd3f495cf5
ep_bytes: ff250020400000000000000000000000
timestamp: 2016-01-17 03:16:22

Version Info:

Translation: 0x0000 0x04b0
FileDescription: InstallShield
FileVersion: 1.0.0.0
InternalName: Stronghold Crusader 2 - InstallShield Wizard.exe
LegalCopyright: Copyright © 2015
OriginalFilename: Stronghold Crusader 2 - InstallShield Wizard.exe
ProductName: InstallShield
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Razy.975292 also known as:

BkavW32.Common.25B0322F
LionicTrojan.Win32.Surveyer.4!c
Elasticmalicious (high confidence)
DrWebTrojan.SurveyerNET.8
MicroWorld-eScanGen:Variant.Razy.975292
FireEyeGen:Variant.Razy.975292
SkyhighArtemis!Trojan
McAfeeArtemis!01264CA70E18
Cylanceunsafe
SangforTrojan.Msil.Surveyer.Vko5
AlibabaTrojan:MSIL/Surveyer.770fc2b2
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderThetaGen:NN.ZemsilF.36802.@t0@aKSxmIe
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Surveyer.GF
TrendMicro-HouseCallTROJ_GEN.R002C0XBE24
KasperskyHEUR:Trojan.MSIL.Hesv.gen
BitDefenderGen:Variant.Razy.975292
TencentMalware.Win32.Gencirc.14028f2a
EmsisoftGen:Variant.Razy.975292 (B)
F-SecureHeuristic.HEUR/AGEN.1308023
VIPREGen:Variant.Razy.975292
TrendMicroTROJ_GEN.R002C0XBE24
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
IkarusTrojan.MSIL.Surveyer
JiangminTrojan.MSIL.ambsb
GoogleDetected
AviraHEUR/AGEN.1308023
Antiy-AVLTrojan/MSIL.Surveyer
MicrosoftTrojan:Win32/Phonzy.A!ml
XcitiumMalware@#2emshwjw1uukc
ArcabitTrojan.Razy.DEE1BC
ZoneAlarmHEUR:Trojan.MSIL.Hesv.gen
GDataGen:Variant.Razy.975292
VBA32Trojan.MSIL.Hesv
ALYacGen:Variant.Razy.975292
MalwarebytesGeneric.Malware.AI.DDS
RisingTrojan.Surveyer!8.7C2 (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
Cybereasonmalicious.70e18a
DeepInstinctMALICIOUS

How to remove Razy.975292?

Razy.975292 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment