Malware

Razy.395454 malicious file

Malware Removal

The Razy.395454 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.395454 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
miicrosoft.hopto.org

How to determine Razy.395454?


File Info:

crc32: C5E85C5C
md5: a7d210435aab894f4388cf6109405f61
name: A7D210435AAB894F4388CF6109405F61.mlw
sha1: d6fd12c7e42bc83d628d685256b6c9e9e7f60837
sha256: 1a5597d88b8ed52629a06275ff3f65f46697a7003399fdaf45307b48d4a9c5b3
sha512: 5e9c4994d367a26b27ecd7dd7c4a896c5ac39841cd09b15e35db9fdcf9060d40d5c3ad81ae939c92eb1d3f2480fb415bbbfe29c3ecf1ee635027fa27c6927b87
ssdeep: 3072:5YIEK13QtCat4rM426c1KadD/3pCfjnOFxiG9:5YILdfat22LMoD/34LO
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2018
Assembly Version: 1.0.0.0
InternalName: max.bayne.exe
FileVersion: 1.0.0.0
ProductName: max.bayne
ProductVersion: 1.0.0.0
FileDescription: max.bayne
OriginalFilename: max.bayne.exe

Razy.395454 also known as:

K7AntiVirusTrojan ( 005224811 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop7.57220
CynetMalicious (score: 99)
ALYacGen:Variant.Razy.395454
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 005224811 )
Cybereasonmalicious.35aab8
SymantecBackdoor.Ratenjay
ESET-NOD32a variant of MSIL/Kryptik.MDR
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Packed.Msilperseus-9802572-0
KasperskyHEUR:Trojan.MSIL.Generic
BitDefenderGen:Variant.Razy.395454
NANO-AntivirusTrojan.Win32.Bladabindi.ewrniz
MicroWorld-eScanGen:Variant.Razy.395454
TencentWin32.Trojan.Generic.Lpbe
Ad-AwareGen:Variant.Razy.395454
SophosMal/Generic-S
ComodoMalware@#2xrrpcfwbhg75
BitDefenderThetaGen:NN.ZemsilF.34236.iq0@ayiB8og
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionPacked-XA!A7D210435AAB
FireEyeGeneric.mg.a7d210435aab894f
EmsisoftGen:Variant.Razy.395454 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.bwhmp
AviraHEUR/AGEN.1108921
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.23D1A16
MicrosoftBackdoor:MSIL/Bladabindi
GDataGen:Variant.Razy.395454
McAfeePacked-XA!A7D210435AAB
MAXmalware (ai score=97)
PandaTrj/GdSda.A
IkarusTrojan-Spy.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.GVM!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Razy.395454?

Razy.395454 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment