Malware

How to remove “Razy.551249”?

Malware Removal

The Razy.551249 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.551249 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Razy.551249?


File Info:

name: 853917941AF3F7B517A2.mlw
path: /opt/CAPEv2/storage/binaries/5a5385d92cc345ae16bdde87b983336041e7356e8ded0ea900b170aa479f7329
crc32: 22257AC4
md5: 853917941af3f7b517a2ef783d452347
sha1: 38b2693013ac1e53b527344d199608dac87d556d
sha256: 5a5385d92cc345ae16bdde87b983336041e7356e8ded0ea900b170aa479f7329
sha512: d3f07dd160af4c2f90317bacbfb8d160aa9b265608eb3a9064d60470c8064f91805ad7bf02421e6a93a0ca3639ac4a36ca31689cee403b3849af1665db5f5db4
ssdeep: 6144:rF/KrQudjjZ1cR3ATgkgZGdKspOuGDM1KUtBrZoh1aV6Q:rF/UQudjjZ1cR3AT5gugbMKyrr6Q
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15A14F1123EABDDE1D027CE3C6967D2B90538DEA8CE82660676D86E45FCA11C04FD44A6
sha3_384: 12df2553076cab872a6502036e4906c643147d7b8023747265adc2211c12edaa848904befa35aca3c0896032b6adbda3
ep_bytes: 833defd04200fd8b05f0d0420085c074
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Razy.551249 also known as:

BkavW32.AIDetect.malware2
LionicHacktool.Win32.ArchSMS.3!c
Elasticmalicious (high confidence)
DrWebTrojan.SMSSend.2363
MicroWorld-eScanGen:Variant.Razy.551249
FireEyeGeneric.mg.853917941af3f7b5
CAT-QuickHealTrojan.Kanots.A
McAfeePWS-Zbot.gen.ael
CylanceUnsafe
ZillyaTrojan.ArchSMS.Win32.33229
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 7000000f1 )
AlibabaTrojanPSW:Win32/ArchSMS.31c5b150
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.41af3f
BitDefenderThetaGen:NN.ZexaF.34212.mGX@aSICpwik
VirITTrojan.Win32.SMSSend.DMX
CyrenW32/Trojan.CCU.gen!Eldorado
SymantecPacked.Generic.382
ESET-NOD32Win32/Spy.Zbot.YW
ClamAVWin.Trojan.Zbot-58757
KasperskyHEUR:Hoax.Win32.ArchSMS.heur
BitDefenderGen:Variant.Razy.551249
NANO-AntivirusTrojan.Win32.SmsSend.cbobaq
SUPERAntiSpywareTrojan.Agent/Gen-Zbot
AvastWin32:Susn-AU [Trj]
TencentMalware.Win32.Gencirc.10c42e1c
Ad-AwareGen:Variant.Razy.551249
TACHYONTrojan-Spy/W32.ZBot.197633
EmsisoftGen:Variant.Razy.551249 (B)
ComodoApplicUnwnt.Win32.Hoax.ArchSMS.SIE@4p73hg
BaiduWin32.Virus.Krap.a
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.AdwareFileTour.ch
SophosMal/Generic-R + Mal/EncPk-AEH
IkarusTrojan-Downloader.Win32.CodecPack
JiangminWorm/Kolab.lyp
eGambitUnsafe.AI_Score_95%
AviraTR/Drop.Flux.B
Antiy-AVLTrojan/Generic.ASMalwS.170A95
MicrosoftPWS:Win32/Zbot!CI
GDataGen:Variant.Razy.551249
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.R27310
Acronissuspicious
VBA32TScope.Malware-Cryptor.SB
ALYacGen:Variant.Razy.551249
MAXmalware (ai score=100)
MalwarebytesMachineLearning/Anomalous.100%
APEXMalicious
RisingSpyware.Voltar!1.AF1D (CLOUD)
YandexTrojan.GenAsa!BjtHSrs9Z5c
SentinelOneStatic AI – Malicious PE
FortinetW32/Zbot.EQPB!tr
WebrootW32.InfoStealer.Zeus
AVGWin32:Susn-AU [Trj]
PandaTrj/Pacrypt.D
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Razy.551249?

Razy.551249 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment