Malware

What is “Razy.161463”?

Malware Removal

The Razy.161463 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.161463 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Razy.161463?


File Info:

crc32: CF46FB2B
md5: d5fcc002bd58efc8f1c64714999c7899
name: D5FCC002BD58EFC8F1C64714999C7899.mlw
sha1: cc3d66469f73005c8298f73de9e6d95f3342f1cc
sha256: ce87235b88037ac7527c67d9e8f95767a7a204dabe43cfbf840ad113026b2047
sha512: 3d7171ca312cd7bdf407707d73970e041381bbe9d14a7e6f378b46e152f01b0976ff6fb5afe2b0b36f245f3ee840cb589e615982f6af7a47fafb31802e0a7e12
ssdeep: 6144:p0E1mg/PWdvDbXgwrxqNqXAj8uY3C7hvYNyQ9FQ+aRP0q9wiRe4:KE1LGhnQwrxqNqQjbY3CFYNopQ4
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2015 DevTronic
FileVersion: 4.3.5.1
CompanyName: DevTronic
FileDescription: Generatrs Hackers Tokens Courtrooms Tui
LegalTrademarks: Copyright 2015 DevTronic
Comments: Generatrs Hackers Tokens Courtrooms Tui
ProductName: Augmentation
ProductVersion: 4.3.5.1
PrivateBuild: 4.3.5.1
Translation: 0x0409 0x04b0

Razy.161463 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.SageCrypt.j!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.10180
CAT-QuickHealTrojan.MauvaiseRI.S5244754
ALYacGen:Variant.Razy.161463
CylanceUnsafe
ZillyaTrojan.SageCrypt.Win32.213
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaRansom:Win32/generic.ali2000010
K7GWTrojan ( 004f76a01 )
K7AntiVirusTrojan ( 004f76a01 )
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Filecoder.NHQ
APEXMalicious
AvastFileRepMalware
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.161463
NANO-AntivirusTrojan.Win32.AD.epfexf
MicroWorld-eScanGen:Variant.Razy.161463
TencentMalware.Win32.Gencirc.10ba7488
Ad-AwareGen:Variant.Razy.161463
SophosML/PE-A
BitDefenderThetaGen:NN.ZexaE.34110.Au0@aSdmyxki
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_MILICRY.F117DP
McAfee-GW-EditionBehavesLike.Win32.Downloader.gh
FireEyeGeneric.mg.d5fcc002bd58efc8
EmsisoftGen:Variant.Razy.161463 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.SageCrypt.hi
AviraHEUR/AGEN.1109748
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.1F56240
MicrosoftRansom:Win32/Milicry!rfn
ArcabitTrojan.Razy.D276B7
GDataGen:Variant.Razy.161463
TACHYONRansom/W32.SageCrypt.434176
AhnLab-V3Win-Trojan/Sagecrypt.Gen
Acronissuspicious
McAfeeGenericR-JQO!D5FCC002BD58
MAXmalware (ai score=82)
VBA32BScope.Trojan.Khalesi
PandaTrj/CI.A
TrendMicro-HouseCallRansom_MILICRY.F117DP
RisingTrojan.Generic@ML.100 (RDML:9Hq3UJfKqY8Ha2kbwqakFQ)
YandexTrojan.DL.Upatre!VE1bygYGL1M
FortinetW32/Kryptik.GKNI!tr.ransom
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Razy.161463?

Razy.161463 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment