Malware

Razy.224219 removal instruction

Malware Removal

The Razy.224219 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.224219 virus can do?

  • Scheduled file move on reboot detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Creates a copy of itself
  • Harvests cookies for information gathering
  • Created network traffic indicative of malicious activity

Related domains:

fileapi.gyaott.top

How to determine Razy.224219?


File Info:

name: 0AF39C7D0394A057F6EF.mlw
path: /opt/CAPEv2/storage/binaries/8588c91cf78af09da135e02e0181b340be728082a17ea3ab377179351253c6f2
crc32: 45860562
md5: 0af39c7d0394a057f6ef1c60fe7f2a78
sha1: 55280bf6e15dbfce1a52a1ca74c48ac3762af5e9
sha256: 8588c91cf78af09da135e02e0181b340be728082a17ea3ab377179351253c6f2
sha512: 6956088745633a649dc95e2f49b2ca20df948352554fba49a6695f69b077b2b3fda4730f01ce3fa0640785f766d622138986a68b92448626c98ccb6b6ef3d6de
ssdeep: 384:bblK3Az3bscy0Nx5M932zmuh9IR04cZRnJI7vR9:bblSAjbsc9HK9Gdy64e67v/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16862D0CEEA94BE99D1DA8D7C93A2D801F57844BD1F98C70AFFD01C23858F1D0D628656
sha3_384: a6dbbabf5be01397ba21415b38ad5ff771a08b8aa1069c3f5e66a35c7c67bc0d1d3799521dae3914b844e4d089f5d068
ep_bytes: 60be007041008dbe00a0feff57eb0b90
timestamp: 2021-11-20 08:13:48

Version Info:

0: [No Data]

Razy.224219 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader44.3757
MicroWorld-eScanGen:Variant.Razy.224219
FireEyeGeneric.mg.0af39c7d0394a057
ALYacGen:Variant.Razy.224219
CylanceUnsafe
ZillyaTrojan.Agent.Win32.2570933
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 005811d21 )
AlibabaTrojanDownloader:Win32/Generic.ef6653f3
K7GWTrojan-Downloader ( 005811d21 )
Cybereasonmalicious.d0394a
BitDefenderThetaGen:NN.ZexaF.34294.amHfaapMNkm
CyrenW32/Dridex.EP.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.FTV
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Generic-9907950-0
KasperskyTrojan.Win32.Agent.xakxin
BitDefenderGen:Variant.Razy.224219
TencentMalware.Win32.Gencirc.10cf8c34
Ad-AwareGen:Variant.Razy.224219
SophosMal/Generic-S
VIPRETrojan.Win32.Agent.xfc (v)
TrendMicroTROJ_GEN.R002C0GKN21
McAfee-GW-EditionRDN/Generic Downloader.x
EmsisoftGen:Variant.Razy.224219 (B)
IkarusTrojan-Downloader
JiangminTrojan.Agent.dsck
AviraTR/Downloader.Gen
Antiy-AVLTrojan/Generic.ASBOL.C4EC
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GridinsoftRansom.Win32.Sabsik.sa
GDataWin32.Trojan.PSE.1ETEWJE
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4786956
Acronissuspicious
McAfeeRDN/Generic Downloader.x
MAXmalware (ai score=88)
VBA32BScope.Backdoor.Androm
MalwarebytesTrojan.Downloader
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0GKN21
YandexTrojan.DL.Agent!f+NnmkpDJU4
SentinelOneStatic AI – Malicious PE
FortinetW32/Agent.FTV!tr.dldr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Razy.224219?

Razy.224219 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment