Malware

Razy.215304 removal instruction

Malware Removal

The Razy.215304 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.215304 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Razy.215304?


File Info:

crc32: F0A2581D
md5: a8817052d4073eb1ef3903daff73dbbd
name: A8817052D4073EB1EF3903DAFF73DBBD.mlw
sha1: acf107fca1f45c653ebd01f3828e968f63099bba
sha256: d9661cad6c8a955e274fa90f351cf22cede44ecf66e239c89a96b12bd5697ba4
sha512: 4e2cbdc8bc54395a4f59bff85df61e7c70895580534e8dceab8cf4f405977efc92fad356cac660650eb7eb64fdd7000c5d661b9bccbf3bb1eb5b88af0d334a1b
ssdeep: 3072:rb1OCuyeyDKqL5nsAS1GQknMzz0eGK8CKU8TmZuJmAktj4f8xX:rkP6Or1MMKCMmAMtjEK
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 Microsoft 2016
Assembly Version: 15.16.11.10
InternalName: SWIFT_MT103_NZ_ICHASUS99588373773TLSA.exe
FileVersion: 9.16.5.17
CompanyName: Microsoft
ProductName: Coder
ProductVersion: 9.16.5.17
FileDescription: Coder
OriginalFilename: SWIFT_MT103_NZ_ICHASUS99588373773TLSA.exe

Razy.215304 also known as:

K7AntiVirusTrojan ( 005208091 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.215304
CylanceUnsafe
SangforTrojan.Win32.Injector.8
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:MSIL/Injector.d3e3db94
K7GWTrojan ( 005208091 )
Cybereasonmalicious.2d4073
CyrenW32/MSIL.Agent.B.gen!Eldorado
SymantecW32.Golroted
ESET-NOD32a variant of MSIL/Injector.SQM
APEXMalicious
AvastMSIL:Crypt-AAP [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.215304
NANO-AntivirusTrojan.Win32.GenericKD.erhqqg
MicroWorld-eScanGen:Variant.Razy.215304
TencentWin32.Trojan.Generic.Lnnt
Ad-AwareGen:Variant.Razy.215304
SophosMal/Generic-S
ComodoMalware@#2t7kkzccngbvg
F-SecureHeuristic.HEUR/AGEN.1144676
BitDefenderThetaGen:NN.ZemsilF.34266.hm0@ambD@Jf
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_HPSCAREIT.SMZ
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
FireEyeGeneric.mg.a8817052d4073eb1
EmsisoftGen:Variant.Razy.215304 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1144676
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Win32.AGeneric
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftBackdoor:Win32/Bladabindi!ml
ArcabitTrojan.Razy.D34908
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Razy.215304
AhnLab-V3Win-Trojan/MSILKrypt02.Exp
McAfeeArtemis!A8817052D407
MAXmalware (ai score=82)
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_HPSCAREIT.SMZ
YandexTrojan.Agent!Ptr/WFvzBjo
IkarusTrojan.VB.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Injector.SQM!tr
AVGMSIL:Crypt-AAP [Trj]
Paloaltogeneric.ml

How to remove Razy.215304?

Razy.215304 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment