Malware

How to remove “Razy.21640”?

Malware Removal

The Razy.21640 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.21640 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Starts servers listening on 127.0.0.1:0
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Makes SMTP requests, possibly sending spam or exfiltrating data.
  • Attempts to interact with an Alternate Data Stream (ADS)

Related domains:

auth.smtp.1and1.fr

How to determine Razy.21640?


File Info:

crc32: 9A4B06BB
md5: f0facbeb648b110f583cad6dfd81e361
name: F0FACBEB648B110F583CAD6DFD81E361.mlw
sha1: 3b5da59b4578c0dbdc908b4d02edf7631d7a82ab
sha256: 68a1087bb2736ff082806e4206a0eab398d135e4625f3552034d8b8acff40d9e
sha512: c8d032a020eded2647f9ce42efecfc6a6955fd8ddaa0c44260ef4a24c2bcaeda9abb7e3a9a93764c9b406b07e8501b2252ef797f06233267e67d0580e1e66579
ssdeep: 6144:yXWQMbRXn2Huq9O/qWzFFrI9OBGiMD1jT7DtJO:yXWQMbJ2HwPeD9tJO
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2016
Assembly Version: 0.3.0.0
InternalName: FileLocker.exe
FileVersion: 0.3.0.0
CompanyName: File Locker
LegalTrademarks: File Locker
Comments: File Locker
ProductName: File Locker
ProductVersion: 0.3.0.0
FileDescription: File Locker
OriginalFilename: FileLocker.exe

Razy.21640 also known as:

K7AntiVirusTrojan ( 004ddac41 )
DrWebTrojan.DownLoader25.24880
CynetMalicious (score: 99)
ALYacTrojan.Ransom.JobCrypter
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.38731
AlibabaRansom:Win32/Blocker.20b668f7
K7GWTrojan ( 004ddac41 )
Cybereasonmalicious.b648b1
CyrenW32/JobCrypter.A.gen!Eldorado
SymantecTrojan.FakeAV
ESET-NOD32a variant of MSIL/Filecoder.JobCrypter.A
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.kgnr
BitDefenderGen:Variant.Razy.21640
NANO-AntivirusTrojan.Win32.Blocker.esdfqd
MicroWorld-eScanGen:Variant.Razy.21640
TencentWin32.Trojan.Blocker.Edxi
Ad-AwareGen:Variant.Razy.21640
SophosMal/Generic-R + Mal/Ramsil-F
ComodoMalware@#1pjg1knzmdapj
BitDefenderThetaGen:NN.ZemsilF.34170.tm0@aifqg5m
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionRansomware-GCR!F0FACBEB648B
FireEyeGen:Variant.Razy.21640
EmsisoftGen:Variant.Razy.21640 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Blocker.ilq
AviraHEUR/AGEN.1120538
Antiy-AVLTrojan/Generic.ASMalwS.21929BA
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftRansom:MSIL/Nojocrypt.A
GDataGen:Variant.Razy.21640
AhnLab-V3Trojan/Win32.Blocker.C2101090
McAfeeRansomware-GCR!F0FACBEB648B
MAXmalware (ai score=100)
MalwarebytesMalware.AI.1459882626
PandaTrj/GdSda.A
YandexTrojan.Blocker!PC3v9wEJ+nk
IkarusTrojan.MSIL.Filecoder
FortinetMSIL/JobCrypter.B!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Razy.21640?

Razy.21640 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment