Malware

How to remove “Razy.279305”?

Malware Removal

The Razy.279305 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.279305 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Attempts to remove evidence of file being downloaded from the Internet
  • Exhibits behavior characteristic of Nanocore RAT
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz
newhost.publicvm.com
backupnewhost.duckdns.org

How to determine Razy.279305?


File Info:

crc32: B4791F1D
md5: a854bd1a3ff6d359a5e2e76154892444
name: A854BD1A3FF6D359A5E2E76154892444.mlw
sha1: b8de8cb81adbb8cc5456a2100ffd3502548b0c2c
sha256: 8fb35304f24a6348adbd96f2ece69cdc23aa2442cfe28ca910ee31b48fd43632
sha512: ebb2d7a7b43f826ddf84aa6374e2c006fdbc2fb8aa924f485b762546eca349f889bb2db50190ca80755741a15542a90c3b0ff035e354c7186fc24c13a7807b19
ssdeep: 3072:2JEZzJZ5WY+apEbTmFxjpcJslEjqZ4UHtbrObVeHCtEGMyVuz5rMRyJJG+pXSPL:HZT5TbjiJslEjqZ4UHtbYVehjauz5+C
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

Razy.279305 also known as:

K7AntiVirusTrojan ( 0057b88c1 )
Elasticmalicious (high confidence)
DrWebTrojan.Nanocore.427
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.279305
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 0057b88c1 )
Cybereasonmalicious.a3ff6d
CyrenW32/NanoCore.C.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/NanoCore.K
APEXMalicious
AvastWin32:CoinminerX-gen [Trj]
ClamAVWin.Trojan.NanoCore-9852758-0
KasperskyHEUR:Trojan.MSIL.Generic
BitDefenderGen:Variant.Razy.279305
MicroWorld-eScanGen:Variant.Razy.279305
Ad-AwareGen:Variant.Razy.279305
SophosML/PE-A
BitDefenderThetaAI:Packer.7AFD00F525
TrendMicroBKDR_NANOCORE.SMD
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.a854bd1a3ff6d359
EmsisoftGen:Variant.Razy.279305 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1108376
Antiy-AVLTrojan/Generic.ASMalwS.25D766D
MicrosoftBackdoor:MSIL/Nanocore.S!MTB
GDataMSIL.Backdoor.Nancat.I
AhnLab-V3Trojan/Win32.Dynamer.C884764
Acronissuspicious
McAfeeGenericRXHE-IA!A854BD1A3FF6
MAXmalware (ai score=81)
VBA32TScope.Trojan.MSIL
MalwarebytesBackdoor.NanoCore
TrendMicro-HouseCallBKDR_NANOCORE.SMD
RisingBackdoor.NanoCore!1.B6F9 (CLASSIC)
IkarusBackdoor.Rat.Nanocore
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Generic.AP.C18054!tr
AVGWin32:CoinminerX-gen [Trj]

How to remove Razy.279305?

Razy.279305 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment