Malware

Razy.621122 removal

Malware Removal

The Razy.621122 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.621122 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Razy.621122?


File Info:

name: AECF6ACB59669BAA410E.mlw
path: /opt/CAPEv2/storage/binaries/d655a50e1b339663eb8e2a5950e8d811e6a992771ae67bc73e213811886bf3ef
crc32: DE1A3BFC
md5: aecf6acb59669baa410e9d004a4823e5
sha1: 6aac983be5e22fc3f14bf21a3859889be7ad3fcb
sha256: d655a50e1b339663eb8e2a5950e8d811e6a992771ae67bc73e213811886bf3ef
sha512: 9c33403667b7d091b77a3dfe695520b1a99fc899614d7792235549593be5649a89736ae31b8cb555d9ab569db725b0edc01caca543fc53f373a9cb74704165e2
ssdeep: 3072:ZSJKKlLsQ15f1EkdHHO4eGdeu3amfNa4iPxh+uIiDnEcHrS6sAPf7UcwxNo:ZqvDf1ddnaGd6m9qDnVHdPf7U/No
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FDF38DC6F40ACE41E44A2171D24F0D370E7E5A65F8DA264253B0845762EE3A4EB5F3BB
sha3_384: 44c6d4dc5c25a0ad8a2d27830cea3e3f0c70d29a6549d9ea0caf8e1b18bdce8e59a5ef3521b944a91c62ae029b31d549
ep_bytes: 558bec81ec480100008b8dfcfeffff8d
timestamp: 2008-11-06 01:39:50

Version Info:

0: [No Data]

Razy.621122 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Zbot.l!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
McAfeePWS-Zbot.gen.de
CylanceUnsafe
VIPREGen:Variant.Razy.621122
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005485311 )
AlibabaTrojanPSW:Win32/Pakes.0cab0ead
K7GWTrojan ( 005485311 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.Scar.NJ
CyrenW32/Zbot.TUNU-2873
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.JOP
APEXMalicious
ClamAVWin.Trojan.Zbot-12672
KasperskyTrojan.Win32.Pakes.ome
BitDefenderGen:Variant.Razy.621122
NANO-AntivirusTrojan.Win32.Zbot.hdsvm
MicroWorld-eScanGen:Variant.Razy.621122
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.10ba907e
Ad-AwareGen:Variant.Razy.621122
TACHYONTrojan-Spy/W32.ZBot.164993
EmsisoftGen:Variant.Razy.621122 (B)
ComodoTrojWare.Win32.Spy.Zbot.AXUI@4knkm2
DrWebTrojan.PWS.Panda.550
ZillyaTrojan.Zbot.Win32.29453
TrendMicroTROJ_ZBOT.SMUA
McAfee-GW-EditionBehavesLike.Win32.VTFlooder.cm
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.aecf6acb59669baa
SophosML/PE-A + Mal/FakeAV-GQ
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Razy.621122
JiangminTrojanSpy.Zbot.atzq
WebrootW32.Infostealer.Zeus
AviraTR/Crypt.XPACK.Gen2
Antiy-AVLTrojan/Generic.ASMalwS.DF
KingsoftWin32.Troj.Generic.a.(kcloud)
ArcabitTrojan.Razy.D97A42
ViRobotTrojan.Win32.A.Pakes.128079
MicrosoftPWS:Win32/Zbot!ZA
GoogleDetected
AhnLab-V3Spyware/Win32.Zbot.R2782
Acronissuspicious
VBA32BScope.Trojan.Bulta
ALYacGen:Variant.Razy.621122
MAXmalware (ai score=100)
TrendMicro-HouseCallTROJ_ZBOT.SMUA
RisingTrojan.Kryptik!8.8 (TFE:2:xwhsib5FPxS)
YandexTrojanSpy.Zbot!I61HszZLdwY
IkarusTrojan.Win32.Pakes
MaxSecureTrojan.Malware.2607425.susgen
FortinetW32/Goolbot.KA!tr.bdr
BitDefenderThetaGen:NN.ZexaF.34698.kmX@aSugkef
AVGWin32:Trojan-gen
Cybereasonmalicious.b59669
PandaGeneric Malware

How to remove Razy.621122?

Razy.621122 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment