Malware

Razy.192010 malicious file

Malware Removal

The Razy.192010 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.192010 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Installs itself for autorun at Windows startup
  • Collects information to fingerprint the system

Related domains:

chinaquaqua.com

How to determine Razy.192010?


File Info:

crc32: 1FB66F37
md5: 62a7045aa7d156dac70c73f536fea549
name: 62A7045AA7D156DAC70C73F536FEA549.mlw
sha1: 7caf986216d02328a2af6c692eb8da440eb4d1ab
sha256: 13e46474c9c0bb69c6adb1177a22809955e6f90332703db2e2dacd15e41da126
sha512: aee8b4ed633ec3a044cf679549da70a6f7316f73d6fae0fd61225ac1b6e22816329a5fff1adf4991ed234955a6a9786417f10a95e8cb118a94024fe19d8297d8
ssdeep: 6144:HyRH2tcbDXxRRP3Ag/Qey1oyCIKSFdE0uSbHzDnQHLk8NvudJQLEjbIDY:yH2tcJPqeaoyClS/rzb6Lk8YpjMDY
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: (C) Automattic
CompanyName: Automattic
LegalTrademarks: (C) Automattic
Comments: Wrong Watts Advising Sltted Publicize
ProductName: EvolveAdvancement
ProductVersion: 4.5.50.8
FileDescription: Wrong Watts Advising Sltted Publicize
OriginalFilename: EvolveAdvancement
Translation: 0x0409 0x04b0

Razy.192010 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop8.16485
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeArtemis!62A7045AA7D1
CylanceUnsafe
ZillyaTrojan.Foreign.Win32.57952
SangforTrojan.Win32.Save.a
AlibabaRansom:Win32/Foreign.286ffa21
K7GWPassword-Stealer ( 0052cf361 )
K7AntiVirusPassword-Stealer ( 0052cf361 )
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/PSW.Delf.OSA
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Foreign.oaiq
BitDefenderGen:Variant.Razy.192010
NANO-AntivirusTrojan.Win32.MoksSteal.fekjes
MicroWorld-eScanGen:Variant.Razy.192010
TencentWin32.Trojan.Foreign.Wogd
Ad-AwareGen:Variant.Razy.192010
SophosMal/Generic-S
ComodoPacked.Win32.MUPX.Gen@24tbus
BitDefenderThetaGen:NN.ZexaF.34110.umKfaSWksDei
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Injector.fc
FireEyeGeneric.mg.62a7045aa7d156da
EmsisoftGen:Variant.Razy.192010 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Foreign.epv
AviraHEUR/AGEN.1120572
Antiy-AVLTrojan/Generic.ASMalwS.26A9A95
MicrosoftRansom:Win32/StopCrypt!ml
ZoneAlarmTrojan-Ransom.Win32.Foreign.oaiq
GDataGen:Variant.Razy.192010
AhnLab-V3Malware/Win32.Generic.C2576552
MAXmalware (ai score=97)
PandaTrj/CI.A
YandexTrojan.Foreign!ANrbtyXZb7k
IkarusTrojan-Ransom.GandCrab
FortinetW32/Delf.OSA!tr.pws
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Razy.192010?

Razy.192010 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment