Malware

Razy.895022 removal tips

Malware Removal

The Razy.895022 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.895022 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Razy.895022?


File Info:

name: 5D2A526DF6BA7989F52D.mlw
path: /opt/CAPEv2/storage/binaries/fa170a7d47dce69c8ece611d5ad827f590a85bb3d2df55cec8eb0394146125bc
crc32: D8EF007B
md5: 5d2a526df6ba7989f52dd5f2ecfafe9d
sha1: 0aa0056c9efcbf05acbf99b7e4b210712b4ac8c5
sha256: fa170a7d47dce69c8ece611d5ad827f590a85bb3d2df55cec8eb0394146125bc
sha512: 79b6815a5e673d7790a0d82d08dbed3892e1fdf4cd6154d3ff78c76cbd230d7bea12261ce61503956603b37c6fa78f959f7c70960b47eefbcd4a42c2b025b60b
ssdeep: 3072:CVabJJoyVZOshAVOf3xKsBj8+LzNCNpDqN8FfGxx4d8GO0MjqVncffmKM3:CVabJJMeVxhBj8SzN+pRIOO0pcffbM3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DB14F102B9136CE0D113E9FDC72B5AB3573CADF6CF90856133D85E99F9284925B1842B
sha3_384: 6bbc6d04431bcda453cd177c18503c58021d03fc56a367391d22ccad6cdbf2fc0e11459ce09bc18c67bf1fb26c8af42f
ep_bytes: 833debd04200ff8b05ecd0420085c00f
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Razy.895022 also known as:

BkavW32.AIDetect.malware2
LionicHeuristic.File.Generic.00×1!p
tehtrisGeneric.Malware
DrWebTrojan.SMSSend.2363
MicroWorld-eScanGen:Variant.Razy.895022
FireEyeGeneric.mg.5d2a526df6ba7989
CAT-QuickHealTrojan.Kanots.A
McAfeePWS-Zbot.gen.yx
CylanceUnsafe
VIPREGen:Variant.Razy.895022
SangforSuspicious.Win32.Save.a
K7AntiVirusSpyware ( 0039990e1 )
K7GWSpyware ( 0039990e1 )
Cybereasonmalicious.df6ba7
BitDefenderThetaGen:NN.ZexaF.34606.lGX@aSBk2Xgk
CyrenW32/Zbot.YS.gen!Eldorado
SymantecPacked.Generic.382
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.AFHC
APEXMalicious
ClamAVWin.Spyware.Zbot-67840
KasperskyHEUR:Hoax.Win32.ArchSMS.heur
BitDefenderGen:Variant.Razy.895022
NANO-AntivirusTrojan.Win32.Zbot.rhapu
SUPERAntiSpywareTrojan.Agent/Gen-Exploiter
AvastWin32:Downloader-OIE [Trj]
TencentMalware.Win32.Gencirc.10c5b8ef
Ad-AwareGen:Variant.Razy.895022
EmsisoftGen:Variant.Razy.895022 (B)
ComodoApplicUnwnt.Win32.Hoax.ArchSMS.SIE@4p73hg
BaiduWin32.Virus.Krap.a
ZillyaTrojan.Zbot.Win32.60374
TrendMicroTROJ_AGENT_008144.TOMB
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.ch
Trapminemalicious.high.ml.score
SophosML/PE-A + Troj/Zbot-BVN
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Razy.895022
JiangminTrojanDownloader.CodecPack.emn
WebrootW32.Rogue.Gen
GoogleDetected
AviraTR/EggDrop.A
Antiy-AVLTrojan/Generic.ASMalwS.31
ArcabitTrojan.Razy.DDA82E
ViRobotTrojan.Win32.A.Zbot.195584.CS
MicrosoftTrojan:Win32/Zbot.SIBB!MTB
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Downloader.195072.AR
VBA32TrojanSpy.Zbot
ALYacGen:Variant.Razy.895022
MAXmalware (ai score=80)
MalwarebytesTrojan.Downloader
TrendMicro-HouseCallTROJ_AGENT_008144.TOMB
RisingSpyware.Voltar!1.AF1D (CLASSIC)
YandexTrojan.GenAsa!DhlA7xqgkGE
IkarusP2P-Worm.Win32.Palevo
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Zbot.EQPB!tr
AVGWin32:Downloader-OIE [Trj]
PandaTrj/Pacrypt.D
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Razy.895022?

Razy.895022 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment