Malware

About “Razy.835226” infection

Malware Removal

The Razy.835226 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.835226 virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs

Related domains:

wpad.local-net

How to determine Razy.835226?


File Info:

name: 6731846874730F92D50E.mlw
path: /opt/CAPEv2/storage/binaries/2fe1399e5c8c53d9021ff9fabc330aa989c388cc07710f68fafd49867819bec8
crc32: F56F4335
md5: 6731846874730f92d50e0cc828db3ac2
sha1: 7a9d48825f0bab7f898648309723ed2e11adaa7c
sha256: 2fe1399e5c8c53d9021ff9fabc330aa989c388cc07710f68fafd49867819bec8
sha512: 8811d2bfd06a8c566b297186b59b493626a134bbcf85416f34625fade7dc7cc26c2f8ec5382e50914e9a0e118d520d395f1ce2c31f18053d4c30f1afc8963a96
ssdeep: 384:8vwtLg8eyimQ8gUb3c/NTsRAYnoRLqNUixfGUHDOo3lc7AqLjPEMHPS:8Kg8qDUbNAuqeU+jOP7AqLI86
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C204350262D0366FD1624336982247E0FFEFAD1B2A65F7CD1128B11DCFB61F69756222
sha3_384: d4fd6f959c913cca99eaf190de796fe656cff0a9d0b608b0e7796d74ea74faaefa00fd9d76a33584489b1552c12f4a92
ep_bytes: ff250020400000000000000000000000
timestamp: 2020-04-22 20:23:20

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: interface
FileVersion: 1.0.0.0
InternalName: @interface.exe
LegalCopyright: Copyright © 2020
LegalTrademarks:
OriginalFilename: @interface.exe
ProductName: interface
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Razy.835226 also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.835226
FireEyeGeneric.mg.6731846874730f92
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
ALYacGen:Variant.Razy.835226
MalwarebytesTrojan.Crypt
K7AntiVirusTrojan ( 005662d51 )
AlibabaTrojan:Win32/Occamy.86c5a244
K7GWTrojan ( 005662d51 )
Cybereasonmalicious.874730
BitDefenderThetaGen:NN.ZemsilCO.34294.km0@aWA3oql
CyrenW32/MSIL_Tiny.D.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Tiny.DJ
Paloaltogeneric.ml
ClamAVWin.Packed.Ashify-9833473-0
BitDefenderGen:Variant.Razy.835226
SUPERAntiSpywareTrojan.Agent/Gen-Tiny
AvastWin32:TrojanX-gen [Trj]
Ad-AwareGen:Variant.Razy.835226
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXKA-UR!673184687473
EmsisoftGen:Variant.Razy.835226 (B)
IkarusTrojan.MSIL.ClipBanker
GDataGen:Variant.Razy.835226
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1133519
Antiy-AVLTrojan/Generic.ASMalwS.304D447
ArcabitTrojan.Razy.DCBE9A
MicrosoftTrojan:Win32/Occamy.C2F
CynetMalicious (score: 99)
AhnLab-V3Malware/Win32.RL_Generic.C4074945
McAfeeGenericRXKA-UR!673184687473
MAXmalware (ai score=89)
APEXMalicious
YandexTrojan.Tiny!mYutkK94Rks
SentinelOneStatic AI – Suspicious PE
FortinetMSIL/Tiny.DJ!tr
AVGWin32:TrojanX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Razy.835226?

Razy.835226 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment