Malware

Razy.842298 removal guide

Malware Removal

The Razy.842298 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.842298 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Razy.842298?


File Info:

crc32: 6BF34EBE
md5: ff76cda5e51ecb3dd6540cbe877ceded
name: FF76CDA5E51ECB3DD6540CBE877CEDED.mlw
sha1: ccee6daa2a712a59a9693b247d1df67bb2d84976
sha256: 6017b43a075d86bad3ef44edbf65039c3c50f511973595000956c626e8a88d84
sha512: 93d4a75806e9c778993b8ebb6d32a000c8987c9b0d452f057e4e725c11302b11c21e79afb92024aa517b7c11ce7f4f7ec520db8f7d31a3d6eb5831987be19673
ssdeep: 6144:nm9jWvc+V9zzmhmmtQ/F+7hTO9wACfnBB9T2wczH52kidMS:m9jWvt9Oh7QKhq9l4nBBEl/IM
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: paMdVH87ILJ
Assembly Version: 4.2.4.5
InternalName: dfee.exe
FileVersion: 4.1.5.x200b0
CompanyName: paMdVH87ILJ
LegalTrademarks: sbTd4O?)PTP
Comments: sbTd4O?)PTP
ProductName: sbTd4O?)PTP
ProductVersion: 4.1.5.x200b0
FileDescription: paMdVH87ILJ
OriginalFilename: dfee.exe

Razy.842298 also known as:

K7AntiVirusTrojan ( 700000121 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
ALYacGen:Variant.Razy.842298
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaTrojan:MSIL/Kryptik.379719dd
K7GWTrojan ( 700000121 )
Cybereasonmalicious.5e51ec
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.RG
APEXMalicious
AvastMSIL:GenMalicious-DTV [Trj]
ClamAVWin.Packed.Bladabindi-9846769-0
KasperskyTrojan.MSIL.Agent.abuxi
BitDefenderGen:Variant.Razy.842298
NANO-AntivirusTrojan.Win32.Krypt.edmsnx
MicroWorld-eScanGen:Variant.Razy.842298
TencentMsil.Trojan.Agent.Egoc
Ad-AwareGen:Variant.Razy.842298
SophosMal/Generic-S
ComodoMalware@#3uie3zx8kg4up
BitDefenderThetaGen:NN.ZemsilF.34236.Om0@a0JQszm
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionTrojan-FDWX!FF76CDA5E51E
FireEyeGeneric.mg.ff76cda5e51ecb3d
EmsisoftGen:Variant.Razy.842298 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1100375
MicrosoftBackdoor:Win32/Bladabindi!ml
ZoneAlarmTrojan.MSIL.Agent.abuxi
GDataGen:Variant.Razy.842298
McAfeeTrojan-FDWX!FF76CDA5E51E
MAXmalware (ai score=100)
PandaTrj/GdSda.A
YandexTrojan.Kryptik!t5O8qYxKHQA
IkarusTrojan.Msil
FortinetMSIL/Generic.AP.1881BCE!tr
AVGMSIL:GenMalicious-DTV [Trj]
Paloaltogeneric.ml

How to remove Razy.842298?

Razy.842298 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment