Malware

Razy.655159 removal

Malware Removal

The Razy.655159 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.655159 virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Drops a binary and executes it
  • Likely installs a bootkit via raw harddisk modifications
  • Deletes its original binary from disk
  • Attempts to restart the guest VM
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Razy.655159?


File Info:

crc32: 6442533B
md5: 4d566a7b38b575900385dcae99e4cdaf
name: 4D566A7B38B575900385DCAE99E4CDAF.mlw
sha1: 6ca188ff49492752297ac9fb90ee255f6cde4c2a
sha256: fc978a5bd50597660bdfb43a539cc2ee691579e7264096a38e58a38a29f9246d
sha512: 188ae2a44293033205f6df9bcb31fd5425a76bf84e025e3b67bfe260d4e36fe5cd0e4ec98549449444b335ed5f7e2bb7a004c4cdda56910d314fc1ce40318f14
ssdeep: 96:yGNrqC4RquUqCLm8rlTckBcf0hKMqiz/ckhZQt:BrqvqucLm8rrcchKMqiBbQt
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Razy.655159 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.MBRlock.6
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacGen:Variant.Razy.655159
CylanceUnsafe
SangforRansom.Win32.Mbrlock_2.se2
CrowdStrikewin/malicious_confidence_80% (D)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/MBRlock.C
APEXMalicious
AvastWin32:Evo-gen [Susp]
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Locker.a
BitDefenderGen:Variant.Razy.655159
NANO-AntivirusTrojan.Win32.Mbro.cwyevs
ViRobotTrojan.Win32.A.Mbro.139264
MicroWorld-eScanGen:Variant.Razy.655159
Ad-AwareGen:Variant.Razy.655159
SophosML/PE-A
BitDefenderThetaAI:Packer.848455281E
FireEyeGeneric.mg.4d566a7b38b57590
EmsisoftGen:Variant.Razy.655159 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.ifva
AviraTR/Crypt.XPACK.Gen
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/Genasom.DV
ArcabitTrojan.Razy.D9FF37
ZoneAlarmTrojan.Win32.Locker.a
GDataGen:Variant.Razy.655159
AhnLab-V3Trojan/Win32.Mbro.C78489
MAXmalware (ai score=82)
VBA32Trojan.Ransom.5705
MalwarebytesMachineLearning/Anomalous.100%
RisingRansom.MBRlock!1.66BD (CLASSIC)
YandexTrojan.GenAsa!lGGJPPymHD4
IkarusTrojan-Ransom.Mbro
FortinetW32/Generic.AC.1931B!tr
AVGWin32:Evo-gen [Susp]

How to remove Razy.655159?

Razy.655159 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment