Malware

Razy.161191 malicious file

Malware Removal

The Razy.161191 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.161191 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Sniffs keystrokes
  • Executed a process and injected code into it, probably while unpacking
  • Exhibits behavior characteristic of iSpy Keylogger
  • Interacts with known DarkComet registry keys
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Creates known Fynloski/DarkComet mutexes

Related domains:

frankmahama0018.hopto.org

How to determine Razy.161191?


File Info:

crc32: FC4E0977
md5: b640117339e43ffdbd2293206fc5c636
name: B640117339E43FFDBD2293206FC5C636.mlw
sha1: 8c54616c34504dbadd631547f10303752140a941
sha256: 1e8e426f21926763db598c40752fae1c194ef8503a114d6c66f1af9b0775c743
sha512: 065b10450e318242d55e115988bfbe10b15e053eb04377c4e572947efdfc4ff4f730a8d7f1644b2615372f510ba9e6f4834b37ed3e3569df6d2c971b45cf54c9
ssdeep: 12288:Y9O+cmWEnJbeTV2P+pdiwe5T0Qi1S6lEnJtBO/7vr97bODU+2Vbo15wLFH:Y0mWEnJqTS+T40v06lEJLO/XJNhF
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

Razy.161191 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Inject1.4287
MicroWorld-eScanGen:Variant.Razy.161191
FireEyeGeneric.mg.b640117339e43ffd
McAfeeArtemis!B640117339E4
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.Razy.161191
K7GWTrojan ( 005036651 )
K7AntiVirusTrojan ( 005036651 )
BitDefenderThetaGen:NN.ZemsilF.34608.6qZ@auu4h!d
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:PWSX-gen [Trj]
ClamAVWin.Packed.Razy-6849099-0
KasperskyTrojan-Ransom.Win32.Blocker.dvjn
AlibabaTrojan:Win32/runner.ali1000123
NANO-AntivirusTrojan.Win32.Blocker.enocii
AegisLabTrojan.Win32.Blocker.j!c
RisingRansom.Blocker!8.12A (CLOUD)
Ad-AwareGen:Variant.Razy.161191
EmsisoftGen:Variant.Razy.161191 (B)
F-SecureTrojan.TR/Dropper.Gen
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
SophosML/PE-A + Troj/MSIL-JHH
IkarusTrojan-Spy.Agent
JiangminTrojan.Blocker.gtv
eGambitTrojan.Generic
AviraTR/Dropper.Gen
Antiy-AVLTrojan[Ransom]/Win32.Blocker.dvjn
MicrosoftBackdoor:Win32/Fynloski
ArcabitTrojan.Razy.D275A7
ZoneAlarmTrojan-Ransom.Win32.Blocker.dvjn
GDataGen:Variant.Razy.161191
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.RL_Generic.C3530246
VBA32Hoax.Blocker
ALYacGen:Variant.Razy.161191
MAXmalware (ai score=86)
MalwarebytesMachineLearning/Anomalous.96%
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.DNB
TencentWin32.Trojan.Blocker.Pefg
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Injector.MEG!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HgIASOkA

How to remove Razy.161191?

Razy.161191 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment