Malware

Razy.377872 (B) malicious file

Malware Removal

The Razy.377872 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.377872 (B) virus can do?

  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Performs some HTTP requests
  • Attempts to remove evidence of file being downloaded from the Internet
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • A system process is generating network traffic likely as a result of process injection
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself

Related domains:

milliaoin.info
lionoi.adygeya.su
ionoiddi.mangyshlak.su
missidiowi.xyz
io90s8dudi.xyz

How to determine Razy.377872 (B)?


File Info:

crc32: 133332A2
md5: f166e6dd969ec235ba9623c8f4fe04d4
name: F166E6DD969EC235BA9623C8F4FE04D4.mlw
sha1: 8f2acae30a77387db49af93ebd4b014b8e102d29
sha256: 2bf26fe0f26585989ff9c23160867c05fbb817f6565266ce9faeda9291b4b89b
sha512: 498c59a1563b2d39fd96a26ef6ed08f8a709f82a43f79202fc62f7a5650ef5ea380063b178137b81fca373537c351a1abe5ec5e7a0f0938dd2e8bd306f9d42a0
ssdeep: 3072:3DuzntrT8uRAhEhzxIwakk8m0EEeu0yvvRAg0FujT0xwG2rE40leJT:zuzntrHbZx3a/0Ek02AOf0KrE7st
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: sgfnghmj.exe

Razy.377872 (B) also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053d5971 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.25976
MicroWorld-eScanGen:Variant.Razy.377872
ALYacGen:Variant.Razy.377872
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Kryptik.b2940e92
K7GWTrojan ( 0053d5971 )
Cybereasonmalicious.d969ec
CyrenW32/GandCrypt.F.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Kryptik.GJUP
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.377872
NANO-AntivirusTrojan.Win32.Propagate.fhsxok
ViRobotTrojan.Win32.GandCrab.254976
TencentWin32.Trojan.Generic.Eawk
Ad-AwareGen:Variant.Razy.377872
SophosMal/Generic-S + Mal/GandCrab-B
ComodoTrojWare.Win32.Ransom.Gandcrab.GJ@7tcda3
BitDefenderThetaGen:NN.ZexaF.34790.nu0@au9Vn4dG
McAfee-GW-EditionBehavesLike.Win32.MultiPlug.dh
FireEyeGeneric.mg.f166e6dd969ec235
EmsisoftGen:Variant.Razy.377872 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.GandCrypt.dx
AviraHEUR/AGEN.1103434
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.27C2F7E
MicrosoftTrojan:Win32/Occamy.C2B
GDataGen:Variant.Razy.377872
AhnLab-V3Win-Trojan/Gandcrab07.Exp
Acronissuspicious
McAfeePacked-FKN!F166E6DD969E
MAXmalware (ai score=100)
VBA32BScope.Trojan.Fuerboos
MalwarebytesTrojan.Agent
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.100 (RDML:1jEyHbsSycJNkJwo3XJsnA)
YandexTrojan.GenAsa!d4BH8v4g1xs
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.CHZN!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HgIASOYA

How to remove Razy.377872 (B)?

Razy.377872 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment