Malware

Should I remove “Razy.895915”?

Malware Removal

The Razy.895915 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.895915 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Harvests credentials from local FTP client softwares

How to determine Razy.895915?


File Info:

name: 9195B00F1CD85084B05E.mlw
path: /opt/CAPEv2/storage/binaries/50a43d6ba803201e7e9a8919bad55b2658fd25b071c401c3fe046cc2042502bf
crc32: 222D21BF
md5: 9195b00f1cd85084b05ebb4aa503f97f
sha1: 71a9d01dcd42b5e82edd8235b1367b4b35875949
sha256: 50a43d6ba803201e7e9a8919bad55b2658fd25b071c401c3fe046cc2042502bf
sha512: 619586be4a18088e871abc981ea23925e860f1dfddb8f2c547e845cdf21b80ac9558d59c9fd5e4a1dc6bcd62e8cacabe73c577d83ea62115be66ef573b45c03d
ssdeep: 3072:KxY8N9KNvPzBW0aKbNM2NvPzBW0JJ2paikNkzH3+ziC:KxtbgI0XI0DxikNkzH4iC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T113A4C0E6A045C9F4D3EA973377478337F83074ED0BBA9A1A36595E52E06C6F43261381
sha3_384: 3251294ba12a03e59bd4d48159bb0bd88836690c3d247a01fa28c4621fda54fea31d29d00434e4f355c43fafa4c445e5
ep_bytes: 558bec83c49068516e344d515152ff75
timestamp: 2006-08-26 00:07:47

Version Info:

0: [No Data]

Razy.895915 also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Packed.1924
CynetMalicious (score: 100)
FireEyeGeneric.mg.9195b00f1cd85084
McAfeeArtemis!9195B00F1CD8
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.98692
SangforBackdoor.Win32.Votwup.8
K7AntiVirusTrojan ( 0055dd191 )
AlibabaBackdoor:Win32/Votwup.8b1f9f7f
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.f1cd85
BitDefenderThetaGen:NN.ZexaF.34212.CCW@aq7qDjoc
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.LRK
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.895915
NANO-AntivirusTrojan.Win32.PornoBlocker.dhzyd
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
MicroWorld-eScanGen:Variant.Razy.895915
AvastWin32:MalOb-FT [Cryp]
TencentWin32.Trojan.Kryptik.Hsif
Ad-AwareGen:Variant.Razy.895915
SophosMal/Generic-S
ComodoMalware@#3hxmrb0924ohv
VIPREPacked.Win32.PWSZbot.gen (v)
McAfee-GW-EditionBehavesLike.Win32.Android.gz
EmsisoftGen:Variant.Razy.895915 (B)
IkarusTrojan.Win32.Crypt
GDataGen:Variant.Razy.895915
JiangminTrojan/PornoBlocker.bda
AviraTR/Crypt.XPACK.Gen2
Antiy-AVLTrojan/Generic.ASMalwS.18DDE21
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:Win32/Votwup.B
SentinelOneStatic AI – Malicious PE
AhnLab-V3Trojan/Win32.Zbot.R2835
ALYacGen:Variant.Razy.895915
VBA32Trojan.Zeus.EA.0999
APEXMalicious
RisingBackdoor.Votwup!8.87E (C64:YzY0OgdVVmQycWmk)
YandexTrojan.Agent!N+iZ2o/MUbk
MAXmalware (ai score=100)
eGambitGeneric.Malware
AVGWin32:MalOb-FT [Cryp]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Razy.895915?

Razy.895915 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment