Malware

What is “Razy.807424”?

Malware Removal

The Razy.807424 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.807424 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Attempts to create or modify system certificates

Related domains:

i.imgur.com
printscr33n.us

How to determine Razy.807424?


File Info:

crc32: 67F2855E
md5: 25b262cf1eec043a2514df2b143d9b2f
name: 25B262CF1EEC043A2514DF2B143D9B2F.mlw
sha1: b8af6c978a18683e0c9ae49122d4daac3fd14b56
sha256: f19dd5b58aebb3aac654b32e7d61929f9ff0ba9f9b9d54cd00e7f1b9592c80b6
sha512: befb4282e75b4a2cc0f127ed9419a6883bcd3f070776a26b32af2744fdb42e05f63332c9e97488b8d4e60ed4cff28b5a822b466a8f0d113fc9f51232f584b9e4
ssdeep: 3072:iilHQQmjDc/19aqao9KqKYD5i3Hwua64vxR2X8PU/cYeMVnjXpuePLazZY3vWiW:VHQZDcdnUA5i3yXn2X/7VnbMsa6fsHQ
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: screenshot221
Assembly Version: 1.0.0.0
InternalName: screenshot221.exe
FileVersion: 1.0.0.0
CompanyName: screenshot221
LegalTrademarks: screenshot221
Comments: screenshot221
ProductName: screenshot221
ProductVersion: 1.0.0.0
FileDescription: screenshot221
OriginalFilename: screenshot221.exe

Razy.807424 also known as:

DrWebTrojan.DownLoader23.4631
MicroWorld-eScanGen:Variant.Razy.807424
McAfeeArtemis!25B262CF1EEC
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Razy.807424
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.f1eec0
BitDefenderThetaGen:NN.ZemsilF.34590.nm0@aaKRvhk
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Blocker.eixxwx
AegisLabTrojan.Win32.Generic.4!c
RisingRansom.Blocker!8.12A (CLOUD)
Ad-AwareGen:Variant.Razy.807424
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1125808
ZillyaBackdoor.PePatch.Win32.102484
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.25b262cf1eec043a
EmsisoftGen:Variant.Razy.807424 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDropper.Dapato.vij
AviraHEUR/AGEN.1125808
MAXmalware (ai score=100)
Antiy-AVLTrojan[Ransom]/Win32.Blocker
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Dynamer!rfn
ArcabitTrojan.Razy.DC5200
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Razy.807424
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.807424
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Spy.Agent.ASO
TencentWin32.Trojan.Generic.Hryw
YandexTrojan.Blocker!/MoueCYSsQw
eGambitUnsafe.AI_Score_100%
FortinetW32/Blocker.JRDB!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360HEUR/QVM03.0.79A7.Malware.Gen

How to remove Razy.807424?

Razy.807424 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment