Malware

Razy.795239 malicious file

Malware Removal

The Razy.795239 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.795239 virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Razy.795239?


File Info:

name: B211C18A659E224C4B4A.mlw
path: /opt/CAPEv2/storage/binaries/084766d0c59643fffff4c1a16e93c5bad8a97b084f28c0bf57d844df9ac2e923
crc32: 8FCB96F2
md5: b211c18a659e224c4b4a13ac1ff61d91
sha1: a57b601b023165ed411741dfc850baa1bc3bcd0a
sha256: 084766d0c59643fffff4c1a16e93c5bad8a97b084f28c0bf57d844df9ac2e923
sha512: 43e79ea09350064e2ca10c481c1a13a0649fe25735c3ff57b3b318fd689f80bdfd140aaf3d59d264622adbdea6b95afabc051252250a09dc0f0e9aac4a1385cb
ssdeep: 6144:WA0ynNCu8MaLKszZ6H5H0tmJ2U5M53nq+vtecGCmGuDvbzOmCC/a27j/TaMsr7:jBEmIuamN5MFrGeub/OmCCL7Taf7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BEB4D773FD870600E5EB1237C09BB91443A2C94573ABE7226A9193960F537EEEC6F191
sha3_384: 971113f22d308d5cd788b61e43f51b75ebeb77ad21ab358ea0491ecc7763f66d1331c9b435cf7f636c253c755d1c8380
ep_bytes: ff250020400000000000000000000000
timestamp: 2058-09-26 10:11:46

Version Info:

Translation: 0x0000 0x04b0
Comments: ვდგრთავთთდდაკრპდპრკპდდადგპატავგდრდვადხრპავდგგატაკგ
CompanyName: ვდგრთავთთდდაკრპდპრკპდდადგპატავგდრდვადხრპავდგგატაკგ
FileDescription: ვდგრთავთთდდაკრპდპრკპდდადგპატავგდრდვადხრპავდგგატაკგ
FileVersion: 2.2.2.2
InternalName: JoooO.STUB.OoooJ.exe
LegalCopyright: Copyright © 2020 ვდგრთავთთდდაკრპდპრკპდდადგპატავგდრდვადხრპავდგგატაკგ
LegalTrademarks: ვდგრთავთთდდაკრპდპრკპდდადგპატავგდრდვადხრპავდგგატაკგ
OriginalFilename: JoooO.STUB.OoooJ.exe
ProductName: ვდგრთავთთდდაკრპდპრკპდდადგპატავგდრდვადხრპავდგგატაკგ
ProductVersion: 2.2.2.2
Assembly Version: 2.2.2.2

Razy.795239 also known as:

LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.795239
FireEyeGeneric.mg.b211c18a659e224c
McAfeeArtemis!B211C18A659E
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005346781 )
AlibabaTrojan:MSIL/Kryptik.b3fda5bc
K7GWTrojan ( 005346781 )
Cybereasonmalicious.a659e2
BitDefenderThetaGen:NN.ZemsilF.34212.Fm0@aeYlODf
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.OIQ
KasperskyUDS:Trojan.Multi.GenericML.xnet
BitDefenderGen:Variant.Razy.795239
NANO-AntivirusTrojan.Win32.Kryptik.idcuhk
AvastWin32:Trojan-gen
Ad-AwareGen:Variant.Razy.795239
EmsisoftGen:Variant.Razy.795239 (B)
ComodoMalware@#3mjm2sgd5uf96
ZillyaTrojan.Kryptik.Win32.2703730
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
IkarusBackdoor.MSIL.Bladabindi
GDataGen:Variant.Razy.795239
AviraTR/Dropper.Gen
MAXmalware (ai score=89)
MicrosoftTrojan:Win32/Zpevdo.B
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.795239
APEXMalicious
RisingMalware.Obfus/MSIL@AI.100 (RDM.MSIL:QbewGjK31KvZstCtHjwqQQ)
YandexTrojan.Kryptik!i6dOVc1zpfY
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.OIQ!tr
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Razy.795239?

Razy.795239 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment