Malware

Razy.841420 malicious file

Malware Removal

The Razy.841420 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.841420 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • Collects information about installed applications
  • Attempts to modify proxy settings

How to determine Razy.841420?


File Info:

crc32: CC3994A9
md5: 0a1278a06a4d7bf4b0a152fccf9b8863
name: 0A1278A06A4D7BF4B0A152FCCF9B8863.mlw
sha1: 0908c23b283f3b4b361b24b2c6716c178d0cc6b3
sha256: e8048d57153281e57b4c3937346165aa89f802c9d17c34045b23d2f946817e40
sha512: 89d4776eeed59aebf209fbca578ac8f78dcd677d8c8e2de764755ad4771ce1308e35839aae1223fa13fdef96a1ec9b89b207f068cf22bf43586e0bcecfc73b3c
ssdeep: 12288:llXKhZVSOww88nuNgEGyKw9lQJm4Drh0XJWhPJjiHYgPa8BvxY:7yLwVROPXwH+Dt0gPJji9PNY
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 2011 Sudden instant Corporation. All rights reserved
InternalName: Language.dll
FileVersion: 2.3.3.763 Applecatch
CompanyName: Sudden instant
Stretch: Happen silent
ProductName: Sudden instant Control think
ProductVersion: 2.3.3.763
FileDescription: Control think
OriginalFilename: Language.dll
Translation: 0x0409 0x04b0

Razy.841420 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.841420
FireEyeGeneric.mg.0a1278a06a4d7bf4
Qihoo-360Win32/Trojan.Kryptik.HgkASO0A
McAfeeGenericRXNP-UJ!0A1278A06A4D
CylanceUnsafe
SangforTrojan.Win32.Agent.gen
BitDefenderGen:Variant.Razy.841420
K7GWTrojan ( 00577a4f1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.FBMH
KasperskyTrojan.Win32.Agent.xagjvr
AlibabaTrojan:Win32/GenKryptik.4ee99d6b
AegisLabTrojan.Win32.Agent.4!c
AvastWin32:CrypterX-gen [Trj]
TencentWin32.Trojan.Agent.Eek
Ad-AwareGen:Variant.Razy.841420
EmsisoftTrojan.Agent (A)
F-SecureTrojan.TR/Kryptik.ugnbb
TrendMicroTROJ_GEN.R002C0WBB21
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
IkarusTrojan.Win32.Krypt
AviraTR/Kryptik.ugnbb
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Razy.DCD6CC
AhnLab-V3Malware/Gen.Reputation.C4332695
ZoneAlarmTrojan.Win32.Agent.xagjvr
GDataGen:Variant.Razy.841420
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.841420
MAXmalware (ai score=80)
TrendMicro-HouseCallTROJ_GEN.R002C0WBB21
RisingTrojan.GenKryptik!8.AA55 (CLOUD)
eGambitUnsafe.AI_Score_85%
FortinetW32/GenKryptik.FBMH!tr
AVGWin32:CrypterX-gen [Trj]

How to remove Razy.841420?

Razy.841420 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment