Malware

What is “Razy.129449”?

Malware Removal

The Razy.129449 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.129449 virus can do?

  • Anomalous file deletion behavior detected (10+)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Razy.129449?


File Info:

name: FAF352E7EB4691317E06.mlw
path: /opt/CAPEv2/storage/binaries/b92b1d6884afef0de6b016cf2b41d0d0443832b9477f0f07456eb405b30ceae9
crc32: 524B26D0
md5: faf352e7eb4691317e06ef78b0264cb1
sha1: 0e5273d0b61a92f6d7ce1a43ddc0f96f82b195e0
sha256: b92b1d6884afef0de6b016cf2b41d0d0443832b9477f0f07456eb405b30ceae9
sha512: 4be341210cb7b75c7a6591fe27ea0c0cbce72c54d4d5084209dec9c417c26a7213f2ba0ccc1e63faba61202d6f974399e7eb5deb0efbaa874453a683a747db02
ssdeep: 3072:zTsZB+70AwdxhnCwijJP60r6/8H/xQxn4Hyyt27hYYYYYYYYYYYYYYYYiYYYYYYJ:itAwzdi56Q60fQ3o27Os6ZZXGpDNWL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T106449E427136E2F4E428C83A556371FA67C76DA15E0E6E142059BF3739B22D0AF0D63B
sha3_384: 196422fd3d340694aab881107da8b2f678ca1a917797ebd0fae5dcb7de3dd02aa97fec29aebd6f58a0924f0d948d228d
ep_bytes: 558bece85ef5ffffc300000000000000
timestamp: 2008-02-23 18:43:56

Version Info:

0: [No Data]

Razy.129449 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Packed.21305
MicroWorld-eScanGen:Variant.Razy.129449
FireEyeGeneric.mg.faf352e7eb469131
CAT-QuickHealTrojan.Rimecud.AA
McAfeeW32/Rimecud.gen.g
CylanceUnsafe
VIPREGen:Variant.Razy.129449
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0040fa5f1 )
BitDefenderGen:Variant.Razy.129449
K7GWTrojan ( 0040fa5f1 )
Cybereasonmalicious.7eb469
ArcabitTrojan.Razy.D1F9A9
BitDefenderThetaAI:Packer.1A2B38D720
CyrenW32/Rimecud.M.gen!Eldorado
SymantecW32.Pilleuz!gen14
ESET-NOD32a variant of Win32/Kryptik.IEI
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
RisingMalware.FakeFolder/ICON!1.6AA9 (CLASSIC)
Ad-AwareGen:Variant.Razy.129449
SophosMal/Generic-R + Mal/EncPk-ACO
ComodoTrojWare.Win32.Kryptic.HJM@25m8dn
TrendMicroWORM_PALEVO.SMWX
McAfee-GW-EditionW32/Rimecud.gen.g
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Razy.129449 (B)
IkarusTrojan.Win32.Crypt
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=83)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Razy.129449
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Palevo.R1904
Acronissuspicious
VBA32BScope.Backdoor.Vawtrak
ALYacGen:Variant.Razy.129449
PandaTrj/Rimecud.a
TrendMicro-HouseCallWORM_PALEVO.SMWX
TencentWin32.Trojan.Genome.Ehrn
YandexTrojan.Kryptik!tBi+QI68f14
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Rimecud-G [Trj]
AvastWin32:Rimecud-G [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Razy.129449?

Razy.129449 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment