Malware

How to remove “Razy.819256”?

Malware Removal

The Razy.819256 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.819256 virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Razy.819256?


File Info:

name: 6434476A9B4D2B3E050D.mlw
path: /opt/CAPEv2/storage/binaries/09a61a096fe73c5b1f8bc471d242ad3057f615c4c2beba5e3b6a3244761ce4b8
crc32: 9B17DB05
md5: 6434476a9b4d2b3e050d146f6f27fcd4
sha1: 826f25e60d4a617af05dd715ff43953dd9b4c07d
sha256: 09a61a096fe73c5b1f8bc471d242ad3057f615c4c2beba5e3b6a3244761ce4b8
sha512: 5432ab86e8d07423de3d3c427196c3d1b9365693c1440a6575c41ca37216f49be1d582150ae2c0538ef24f8f5429caef9704ea1a1ad0f629ac475070bcdfa262
ssdeep: 12288:YYVYvjKWgEgKSg3xksXtBlXKfdedL4+3E65usT852ynFVYR:1uvjB/OhZ5jVYR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AE15A6243BE62069F377FF75AED07497B72AB1232601A4D91D92234A8637911DDC2C3E
sha3_384: 07435a6dc5b6246ea4a5d50af67eb3053b84cff767c437b3dfce84d9ac379b4029f041690e98a5a8d9bf735f6845d88f
ep_bytes: ff2500204000302f4832525034787a5a
timestamp: 2101-04-18 20:23:46

Version Info:

Translation: 0x0000 0x04b0
Comments: NoTrial
CompanyName: https://allkey.org
FileDescription: Allkeys
FileVersion: 1.1.2606.2021
InternalName: Allkeys.exe
LegalCopyright: NoTrial © 2021
LegalTrademarks:
OriginalFilename: Allkeys.exe
ProductName: FREE GAMES
ProductVersion: 1.1.2606.2021
Assembly Version: 1.1.2606.2021

Razy.819256 also known as:

Elasticmalicious (high confidence)
FireEyeGeneric.mg.6434476a9b4d2b3e
McAfeeGenericRXND-PF!6434476A9B4D
SangforRiskware.Win32.Uwamson.A
Cybereasonmalicious.a9b4d2
BitDefenderThetaGen:NN.ZemsilF.34114.1m0@aa!oVTc
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
BitDefenderGen:Variant.Razy.819256
MicroWorld-eScanGen:Variant.Razy.819256
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Razy.819256
SophosGeneric PUA IC (PUA)
McAfee-GW-EditionGenericRXND-PF!6434476A9B4D
EmsisoftGen:Variant.Razy.819256 (B)
GDataGen:Variant.Razy.819256
Antiy-AVLTrojan/Generic.ASMalwS.33AF2EC
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Trojan/Win32.CoinMiner.R369698
ALYacGen:Variant.Razy.819256
MAXmalware (ai score=100)
MalwarebytesMalware.AI.4148710423
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:lYWFUxW4AAyv0EsACwMjCw)
SentinelOneStatic AI – Malicious PE
FortinetPossibleThreat
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Razy.819256?

Razy.819256 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment