Malware

Razy.412416 (file analysis)

Malware Removal

The Razy.412416 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.412416 virus can do?

  • Creates RWX memory
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs

How to determine Razy.412416?


File Info:

crc32: E9AEAC07
md5: 492c6f5c4c2653e7287a5f53a6c2391a
name: 492C6F5C4C2653E7287A5F53A6C2391A.mlw
sha1: 860848167a74e01812eb737eab7f554203183527
sha256: 08a700f1a530dc6dab04f90df02ce155a8cf2eedb1bbb77d67b77ee009c96a49
sha512: 9dde59848af60c69ffa7ce675fa90ff5706dda52b3b517bfa9e97beab900482ed40319649682ce629b6379b818ad0bdf55735b431d1b3dd50e613dcbb226fb8f
ssdeep: 768:3h3Jn9oTTj3lpq2EuOYRGoVXkE5A37jYYBL9DJV80c3Ivu+:x34j3+28Y8o2E5M7kY199Vs3Iv5
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2018
Assembly Version: 1.0.0.2
InternalName: Julycondda.exe
FileVersion: 1.0.0.2
CompanyName:
LegalTrademarks:
Comments:
ProductName: Julycondda
ProductVersion: 1.0.0.2
FileDescription: Julycondda
OriginalFilename: Julycondda.exe

Razy.412416 also known as:

K7AntiVirusTrojan ( 004d3df31 )
LionicTrojan.MSIL.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.26547
MicroWorld-eScanGen:Variant.Razy.412416
ALYacGen:Variant.Razy.412416
CylanceUnsafe
ZillyaTrojan.Generic.Win32.232870
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:MSIL/Filecoder.77032d90
K7GWTrojan ( 004d3df31 )
Cybereasonmalicious.c4c265
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Filecoder.AC
APEXMalicious
AvastWin32:Trojan-gen
CynetMalicious (score: 99)
KasperskyHEUR:Trojan-Ransom.MSIL.Generic
BitDefenderGen:Variant.Razy.412416
NANO-AntivirusTrojan.Win32.Ransom.fjiqqs
TencentWin32.Trojan.Raas.Auto
Ad-AwareGen:Variant.Razy.412416
SophosMal/Generic-S + Mal/CrypZxas-A
ComodoMalware@#37y2qv22fqi5n
BitDefenderThetaGen:NN.ZemsilF.34796.dm0@aiz6Y3o
McAfee-GW-EditionBehavesLike.Win32.Trojan.pc
FireEyeGeneric.mg.492c6f5c4c2653e7
EmsisoftGen:Variant.Razy.412416 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.MSIL.kiec
AviraHEUR/AGEN.1115170
Antiy-AVLTrojan/Generic.ASMalwS.28AA26E
MicrosoftTrojan:Win32/Occamy.C
ZoneAlarmHEUR:Trojan-Ransom.MSIL.Generic
GDataGen:Variant.Razy.412416
McAfeeArtemis!492C6F5C4C26
MAXmalware (ai score=88)
VBA32Trojan.Azden
MalwarebytesMalware.AI.4145362229
PandaTrj/GdSda.A
YandexTrojan.Filecoder!2LvxKEO/L0E
IkarusTrojan-Ransom.FileCrypter
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Filecoder.AC!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Generic.HgIASRIA

How to remove Razy.412416?

Razy.412416 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment