Malware

Razy.125163 removal guide

Malware Removal

The Razy.125163 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.125163 virus can do?

  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
0.tcp.ngrok.io

How to determine Razy.125163?


File Info:

crc32: 6271D08F
md5: 8c5624b50939d46b9eee1627269ca01d
name: robux12.exe
sha1: 4ad3050c7650409d814e9c249891f7d7e8cf7b63
sha256: 2d123daaed835ad3ccfe84a2fd14840a8f3665ab62108aa9c21f4f9e9e6b2d92
sha512: 199679b106053ef75f38715ad21ab2e6c144ab3c9a57c04761c107ca640ae466bd9d6d6cdd019750d4fe4aeb18b212beab8815044e6e1abe6ca6df436e18a46f
ssdeep: 768:XXmbfKll5wclMNEroV991ANwAqSq40Y4lr:STkvry74wAqSfj41
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

Razy.125163 also known as:

MicroWorld-eScanGen:Variant.Razy.125163
FireEyeGeneric.mg.8c5624b50939d46b
CAT-QuickHealTrojan.MsilFC.S6060625
McAfeeGenericRXEK-KS!8C5624B50939
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 700000121 )
BitDefenderGen:Variant.Razy.125163
K7GWTrojan ( 700000121 )
Cybereasonmalicious.50939d
Invinceaheuristic
F-ProtW32/Revetrat.A.gen!Eldorado
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
ClamAVWin.Trojan.RevengeRat-6344273-0
GDataGen:Variant.Razy.125163
KasperskyHEUR:Trojan.Win32.RRAT.gen
TencentWin32.Trojan.Rrat.Ecao
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Razy.125163 (B)
ComodoTrojWare.MSIL.Revetrat.A@7osjcj
F-SecureTrojan.TR/ATRAPS.Gen
DrWebBackDoor.RevetRat.2
ZillyaTrojan.Agent.Win32.1339523
TrendMicroTROJ_REVETRAT.SM
SophosMal/Revet-A
SentinelOneDFI – Malicious PE
CyrenW32/Revetrat.A.gen!Eldorado
JiangminTrojan.RRAT.agc
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan/Win32.RRAT
MicrosoftBackdoor:MSIL/RevengeRat.GA!MTB
ArcabitTrojan.Razy.D1E8EB
ZoneAlarmHEUR:Trojan.Win32.RRAT.gen
CynetMalicious (score: 85)
VBA32Backdoor.RevetRat
ALYacGen:Variant.Razy.125163
MAXmalware (ai score=87)
Ad-AwareGen:Variant.Razy.125163
MalwarebytesBackdoor.RevengeRAT
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Agent.APN
TrendMicro-HouseCallTROJ_REVETRAT.SM
RisingBackdoor.Revetrat!1.B8DA (CLOUD)
IkarusBackdoor-Rat.Revenge
eGambitTrojan.Generic
FortinetMSIL/RevengeRat.APN!tr
BitDefenderThetaGen:NN.ZemsilF.34132.xmW@a4Ahted
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360HEUR/QVM03.0.76F6.Malware.Gen

How to remove Razy.125163?

Razy.125163 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment