Malware

Razy.352668 (file analysis)

Malware Removal

The Razy.352668 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.352668 virus can do?

  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Mimics the file times of a Windows system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

How to determine Razy.352668?


File Info:

crc32: CEA529DA
md5: 2064a2bc94c07a63da5114a6d726fde1
name: 2064A2BC94C07A63DA5114A6D726FDE1.mlw
sha1: 34d587c93502f67030c4f3dd023cd695099c5a90
sha256: 51376a3bf96483725873e7b464a483aad3d6d825fc12b7f776ec0c2a5587b309
sha512: 9800588237de5133e13e2f38a098e62a1d880c9c82fc26153d5604222d8a71f20bc62a8820833016279be99af43f5df695a152267f91c50a98a0ed45b9c7dc7d
ssdeep: 1536:/Rh7TAqZOjo/outPrRk19LGjc5IYHWmmGEahpe+Ki19V2://Z/jtPrm3La+IEWZGe6
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Razy.352668 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.DnsChange
MicroWorld-eScanGen:Variant.Razy.352668
FireEyeGeneric.mg.2064a2bc94c07a63
CAT-QuickHealTrojan.DNSChanger
ALYacGen:Variant.Razy.352668
CylanceUnsafe
VIPRETrojan.Win32.Alureon.pb (v)
AegisLabTrojan.Win32.DNSChanger.kZ16
SangforMalware
K7AntiVirusTrojan ( 000219791 )
BitDefenderGen:Variant.Razy.352668
K7GWTrojan ( 000219791 )
Cybereasonmalicious.c94c07
BitDefenderThetaAI:Packer.50D2F1131E
CyrenW32/Trojan2.NNZ
SymantecTrojan.Packed.7
TotalDefenseWin32/Alureon!generic
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Dnschanger-1797
KasperskyTrojan.Win32.DNSChanger.acs
AlibabaTrojanDownloader:Win32/DNSChanger.2a9df6cc
NANO-AntivirusTrojan.Win32.DNSChanger.bkgtlv
Ad-AwareGen:Variant.Razy.352668
SophosML/PE-A + Mal/Behav-196
ComodoTrojWare.Win32.DNSChanger.ACS@k1361
ZillyaTrojan.DNSChanger.Win32.12493
TrendMicroTROJ_DNSCHAN.AB
McAfee-GW-EditionBehavesLike.Win32.Upatre.lc
EmsisoftGen:Variant.Razy.352668 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Alureon.Rootkit
AviraTR/Crypt.XPACK.Gen
eGambitUnsafe.AI_Score_87%
Antiy-AVLTrojan/Win32.DNSChanger
MicrosoftTrojan:Win32/Alureon.gen
ArcabitTrojan.Razy.D5619C
ZoneAlarmTrojan.Win32.DNSChanger.acs
GDataGen:Variant.Razy.352668
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.DNSChanger.R77810
Acronissuspicious
McAfeeDNSChanger.cs
MAXmalware (ai score=100)
VBA32BScope.Trojan.DNSChanger
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/TrojanDownloader.Zlob.BFI
TrendMicro-HouseCallTROJ_DNSCHAN.AB
RisingDownloader.Zlob!8.B37 (TFE:dGZlOgXc0lyY3sVd2g)
YandexTrojan.GenAsa!1sMlg7zKseE
IkarusTrojan.Win32.DNSChanger
FortinetW32/PackRPCrypt.RPA!tr
AVGWin32:ChanCrypt [Cryp]
AvastWin32:ChanCrypt [Cryp]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.6f6

How to remove Razy.352668?

Razy.352668 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment