Malware

Razy.190115 removal

Malware Removal

The Razy.190115 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.190115 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Installs an hook procedure to monitor for mouse events
  • Unusual version info supplied for binary

How to determine Razy.190115?


File Info:

crc32: 156A1792
md5: f79177047ad6810ca7250f4b47590730
name: F79177047AD6810CA7250F4B47590730.mlw
sha1: b8705044143c161b2892610f898bf3302569c39f
sha256: 713091e697da11be47267f5c875ba99eefcb32827b6fd52ec336e21f6962b466
sha512: 9f8088d178fc389eec8b7210d1e6d32dd26a849564cefdd2fc4df485858235c7ee03ed7ed6d4e6dedbee6771868f22544bc30339e6b47ad037f33126ae11fdad
ssdeep: 12288:sn/xDXyorqp0PpIdXnV/FKcg47aVr3Zn+nTXG69:goNp0PidXnVtKLrJnGXG
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 Microsoft 2017
Assembly Version: 1.0.0.0
InternalName: WIRUSLocker.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments: WIRUS
ProductName: Microsoft Browser
ProductVersion: 1.0.0.0
FileDescription: Microsoft Browser
OriginalFilename: WIRUSLocker.exe

Razy.190115 also known as:

K7AntiVirusTrojan ( 700000121 )
ALYacGen:Variant.Razy.190115
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaRansom:Win32/Blocker.edf408c4
K7GWTrojan ( 700000121 )
Cybereasonmalicious.47ad68
SymantecML.Attribute.HighConfidence
ESET-NOD32MSIL/LockScreen.UL
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.kddu
BitDefenderGen:Variant.Razy.190115
NANO-AntivirusTrojan.Win32.Krypt.eqhqii
MicroWorld-eScanGen:Variant.Razy.190115
TencentMalware.Win32.Gencirc.11498f9f
Ad-AwareGen:Variant.Razy.190115
SophosMal/Generic-S
ComodoMalware@#1d858o6oiqfqr
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FireEyeGen:Variant.Razy.190115
EmsisoftGen:Variant.Razy.190115 (B)
SentinelOneStatic AI – Malicious PE
MicrosoftTrojan:Win32/Skeeyah.A!bit
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Variant.Razy.190115
AhnLab-V3Trojan/Win32.Blocker.C2055679
McAfeeArtemis!F79177047AD6
MAXmalware (ai score=85)
VBA32TScope.Trojan.MSIL
MalwarebytesMalware.AI.4016240850
PandaTrj/GdSda.A
RisingRansom.Blocker!8.12A (CLOUD)
YandexTrojan.Blocker!g7Sni5HLjEU
IkarusTrojan.MSIL.LockScreen
FortinetMSIL/Generic.AP.9FBD52!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HgIASOQA

How to remove Razy.190115?

Razy.190115 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment