Malware

What is “Razy.418805”?

Malware Removal

The Razy.418805 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.418805 virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Razy.418805?


File Info:

crc32: D2848D6E
md5: 2129d75d6bf0a79290937be1854bebde
name: upload_file
sha1: 72913b683a9fd20d47dd84e27f2f7110f7c1d2c8
sha256: 2d65f98577cae0d1e463145ab9394a5cc02605d9b6e46e4f98bcaa340d38a3f5
sha512: 9a888fd131cb958438669f942d1b9f52450cb3feebe4626232a66ca50bad292361cbf7ddd065ab737028e3a41ec6685a4a6166a84b198c428d89edf0646ae81c
ssdeep: 6144:aeLmR27vD7itwuLr95+lWSyoEMQRzSeq+RO/kFEPH:a2Xw/qmoEMQ5Seq+RO/kFEP
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 1996-2020 VideoLAN and VLC Authors
Assembly Version: 3.0.10.0
InternalName: Lime_evansty tele 2.0.exe
FileVersion: 3.0.10.0
CompanyName: VideoLAN
LegalTrademarks: VLC media player, VideoLAN and x264 are registered trademarks from VideoLAN
Comments: VLC media player
ProductName: VLC media player
ProductVersion: 3.0.10.0
FileDescription: VLC media player
OriginalFilename: Lime_evansty tele 2.0.exe

Razy.418805 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.418805
FireEyeGeneric.mg.2129d75d6bf0a792
CAT-QuickHealTrojanpws.Msil
McAfeeRDN/AgentTesla
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0056fb821 )
AlibabaTrojanPSW:MSIL/Agensla.edb2645b
K7GWTrojan ( 0056fb821 )
Cybereasonmalicious.d6bf0a
CyrenW32/MSIL_Kryptik.BLX1.ge!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
BitDefenderGen:Variant.Razy.418805
ViRobotTrojan.Win32.Z.Razy.267776.AF
Ad-AwareGen:Variant.Razy.418805
SophosMal/Generic-S
InvinceaMal/Generic-S
McAfee-GW-EditionRDN/AgentTesla
SentinelOneDFI – Malicious PE
GDataGen:Variant.Razy.418805
JiangminTrojan.PSW.MSIL.avpc
AviraTR/Kryptik.mlyrm
eGambitUnsafe.AI_Score_99%
ArcabitTrojan.Razy.D663F5
AegisLabTrojan.MSIL.Agensla.i!c
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.gen
BitDefenderThetaGen:NN.ZemsilF.34590.qm0@auFhFqd
MAXmalware (ai score=84)
ZonerTrojan.Win32.96574
ESET-NOD32a variant of MSIL/GenKryptik.ESST
TencentMsil.Trojan-qqpass.Qqrob.Hnbd
IkarusTrojan.Agent
FortinetW32/Agensla.ESST!tr.pws
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Generic/Trojan.PSW.374

How to remove Razy.418805?

Razy.418805 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment