Malware

How to remove “Razy.600314”?

Malware Removal

The Razy.600314 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.600314 virus can do?

  • At least one process apparently crashed during execution
  • Creates RWX memory
  • Loads a driver
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Attempts to stop active services
  • Attempts to repeatedly call a single API many times in order to delay analysis time

How to determine Razy.600314?


File Info:

crc32: C285488B
md5: 196293d5eef14d9130f706e7531b8db6
name: MIMI-1.18.vmp.exe
sha1: a35565e984f9b528d2c1c11f773e6e39c6aeabb4
sha256: a96ba5b274f007ad79e3990c786849bf61090973c71da19dcfdce6739626e560
sha512: a0fb31257030b12721ad848ce4724896496022b461573d7e843d1676002e1e28d55c1af8e9fff71ab4008333add878a976fb7b7ed8cb03e69e517e875c0551e7
ssdeep: 196608:zBuvmYKOjc4jcJLfbkCpvIj19OhTkirv:zB4mYKOjl2o281OTk
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Razy.600314 also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanGen:Variant.Razy.600314
FireEyeGeneric.mg.196293d5eef14d91
McAfeeArtemis!196293D5EEF1
ALYacGen:Variant.Razy.600314
CylanceUnsafe
SangforMalware
K7AntiVirusAdware ( 0050718d1 )
BitDefenderGen:Variant.Razy.600314
K7GWAdware ( 0050718d1 )
CrowdStrikewin/malicious_confidence_100% (D)
F-ProtW32/Agent.EW.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin64:Trojan-gen
GDataGen:Variant.Razy.600314
Endgamemalicious (high confidence)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
DrWebTrojan.Rootkit.22030
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Razy.600314 (B)
SentinelOneDFI – Malicious PE
CyrenW32/Agent.EW.gen!Eldorado
MAXmalware (ai score=83)
Antiy-AVLGrayWare/Win32.FlyStudio.a
ArcabitTrojan.Razy.D928FA
MicrosoftTrojan:Win32/Wacatac.D!ml
Acronissuspicious
Ad-AwareGen:Variant.Razy.600314
MalwarebytesAdware.DownloadAssistant
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazo0iBDrIoiIyd+3SGp4SfsF)
IkarusTrojan.Dropper.Injector
eGambitHackTool.Generic
FortinetRiskware/Application
BitDefenderThetaGen:NN.ZexaF.34100.@BW@aCWvcgfb
AVGWin64:Trojan-gen
Cybereasonmalicious.984f9b
Qihoo-360Generic/HEUR/QVM19.1.291F.Malware.Gen

How to remove Razy.600314?

Razy.600314 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment