Malware

How to remove “Razy.798210”?

Malware Removal

The Razy.798210 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.798210 virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Razy.798210?


File Info:

name: 2A8E7AB240B29B031D86.mlw
path: /opt/CAPEv2/storage/binaries/21c432a03fc27199da582b27005583a52162ee37501ff6ba75180bf7de655720
crc32: 24B8FA54
md5: 2a8e7ab240b29b031d86a6c8f00910ab
sha1: c76d380d50a8202e0ae33beb08c0b4a75953aff5
sha256: 21c432a03fc27199da582b27005583a52162ee37501ff6ba75180bf7de655720
sha512: 36e26cb08717d4986610f891f489911f88c64f87b0a194ec51184dbcf4e13ce2daf6ae64024491c63d235aae9c58b635935777976fa713306459b5dc2d34484e
ssdeep: 3072:bwilBoENxGlZE9aC1JbBkcG/WPK3JcWfgE5b6Sx331MChivOlmv6hV6r+sgG4NY4:tlBoENr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F764487B4B9C092BCBBED1B97BA0F44AFA808C933B059D5F43CB66C5552B50225C6C6C
sha3_384: e99eabb84424a7fa30fa3913a472cb1fa153b404986afcc0f50ba1478b4d1a2e6827908af076b49d49b603575232cbc5
ep_bytes: ff250020400000000000000000000000
timestamp: 2020-11-22 09:26:11

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: mLTQD.exe
LegalCopyright:
OriginalFilename: mLTQD.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Razy.798210 also known as:

LionicTrojan.MSIL.DOTHETUK.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
FireEyeGeneric.mg.2a8e7ab240b29b03
ALYacGen:Variant.Razy.798210
CylanceUnsafe
ZillyaTrojan.DOTHETUK.Win32.4860
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00573a1f1 )
AlibabaTrojan:Win32/Kryptik.ali2000016
K7GWTrojan ( 00573a1f1 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.YTY
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.MSIL.DOTHETUK.gen
BitDefenderGen:Variant.Razy.798210
MicroWorld-eScanGen:Variant.Razy.798210
AvastWin32:DropperX-gen [Drp]
TencentMsil.Trojan.Dothetuk.Hsta
EmsisoftGen:Variant.Razy.798210 (B)
ComodoMalware@#3rm2vlcgmy5ex
DrWebTrojan.Inject3.9657
TrendMicroTROJ_GEN.R002C0PAV22
McAfee-GW-EditionBehavesLike.Win32.Generic.fz
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.Gen
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataMSIL.Trojan.Kryptik.QI
AhnLab-V3Trojan/Win32.Wacatac.C4229209
McAfeeFareit-FUW!2A8E7AB240B2
MAXmalware (ai score=84)
VBA32TScope.Trojan.MSIL
MalwarebytesMalware.AI.3740301803
TrendMicro-HouseCallTROJ_GEN.R002C0PAV22
RisingMalware.Obfus/MSIL@AI.97 (RDM.MSIL:bDJm7Fr+SEWZaWzVxZTYEQ)
IkarusTrojan.Dropper
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/GenKryptik.CLVF!tr
BitDefenderThetaGen:NN.ZemsilF.34182.tm0@ai2Dm8l
AVGWin32:DropperX-gen [Drp]
Cybereasonmalicious.240b29
PandaTrj/GdSda.A

How to remove Razy.798210?

Razy.798210 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment