Malware

Razy.355473 (file analysis)

Malware Removal

The Razy.355473 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.355473 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Exhibits behavior characteristic of iSpy Keylogger
  • Exhibits possible ransomware file modification behavior
  • Network activity detected but not expressed in API logs
  • Appends a known encryptJJS ransomware file extension to files that have been encrypted
  • Anomalous binary characteristics

How to determine Razy.355473?


File Info:

crc32: 35DCCC2F
md5: 9f080ee5d88db5f315b3f8d44dc0d2cd
name: 9F080EE5D88DB5F315B3F8D44DC0D2CD.mlw
sha1: d68f2fef4ffdc0ff8d52f03d53ac453aafcf4626
sha256: 65c21d9060e86d8a6f5d868b5119f7db178014dbb94753376b705b9dc590f9bf
sha512: d74e09ecdb5afb64c1a17fd36e790f0523a56a4736a1ef245ab47448474ee55ca0bc748aa8fd960c89e3bcfef1287d73f8544db04bf4c571b7ca51cd1bdd8632
ssdeep: 384:cv1tvgwK3n7hEf68jvGdjZdPZWa/4A86hXYIDFW8U6QhxmXzC/klYc3qkgxd5:cvT7mnsVenbm6DFU8oWYc3qkgxd
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: Tree.exe
FileVersion: 0.0.0.0
CompanyName:
LegalTrademarks:
Comments: rw
ProductName:
ProductVersion: 0.0.0.0
FileDescription: rw
OriginalFilename: Tree.exe

Razy.355473 also known as:

LionicTrojan.Win32.Agent.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.Ransom.HiddenTear
CylanceUnsafe
ZillyaTrojan.Agent.Win32.1064892
AlibabaRansom:Win32/FileCrypter.1b0e31dc
Cybereasonmalicious.5d88db
SymantecTrojan Horse
ESET-NOD32a variant of MSIL/Filecoder.ACH
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan-Ransom.Win32.Agent.gen
BitDefenderGen:Variant.Razy.355473
MicroWorld-eScanGen:Variant.Razy.355473
TencentWin32.Trojan.Agent.Hufo
Ad-AwareGen:Variant.Razy.355473
SophosMal/Generic-S
ComodoMalware@#288y1o9u9pasw
BitDefenderThetaGen:NN.ZemsilF.34110.bm0@auh67uj
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.MSIL.TREE.THBAEAI
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.9f080ee5d88db5f3
EmsisoftGen:Variant.Razy.355473 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Agent.bujx
WebrootW32.Trojan.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.2A84291
MicrosoftBackdoor:Win32/Bladabindi!ml
GDataGen:Variant.Razy.355473
AhnLab-V3Trojan/Win32.Ransom.C2725954
McAfeeArtemis!9F080EE5D88D
MAXmalware (ai score=100)
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.MSIL.TREE.THBAEAI
IkarusTrojan-Ransom.FileCrypter
MaxSecureTrojan.Malware.12310942.susgen
FortinetMSIL/Whoopsie.CFD6!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Razy.355473?

Razy.355473 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment