Malware

What is “Razy.463695”?

Malware Removal

The Razy.463695 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.463695 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z3k4nt2.cdmon.org

How to determine Razy.463695?


File Info:

crc32: 196912AB
md5: 3497f1ea0ea4a4d3c1c8a7f4bdbf6da8
name: 3497F1EA0EA4A4D3C1C8A7F4BDBF6DA8.mlw
sha1: 01b60c65c1ae2db625ae13e7e6ef3edb85ce0912
sha256: 4582eaee6d8188a064dee7ad0b0c9707d9d842261e15c6579639b314bc32b25e
sha512: 9bf67c1e1da6ff977d214bd33e11c8aa76bd81c6ba6fa9c0b6ab8f6f26b244da27bff1bcc1ace8a6cdaad51e691b7392b24825c1b47bf839f4857a22a72510f8
ssdeep: 3072:wUeG/9uNL6zv0b9Q+5/8nt1VUxFNfCDg1grHcm+MvE8:wG9BYbXUntPCNfCDO88/
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: LikeThat8
FileVersion: 6456.01.0221
CompanyName: Winrar Software
ProductName: IceCreamPaintJob
ProductVersion: 6456.01.0221
OriginalFilename: LikeThat8.exe

Razy.463695 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner.49361
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.463695
CylanceUnsafe
ZillyaBackdoor.SdBot.Win32.10660
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Blocker.4d40842f
Cybereasonmalicious.a0ea4a
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/AutoRun.IRCBot.FC
APEXMalicious
AvastWin32:VB-TQE [Trj]
ClamAVWin.Trojan.Sdbot-310
KasperskyTrojan-Ransom.Win32.Blocker.jftg
BitDefenderGen:Variant.Razy.463695
NANO-AntivirusTrojan.Win32.Ircbrute.cxgoo
SUPERAntiSpywareTrojan.Agent/Gen-VBInject
MicroWorld-eScanGen:Variant.Razy.463695
Ad-AwareGen:Variant.Razy.463695
SophosMal/Generic-S
ComodoMalware@#3e94cp3gq8rgw
BitDefenderThetaAI:Packer.6383A93620
VIPRETrojan.Win32.Ircbrute
McAfee-GW-EditionBehavesLike.Win32.VBObfus.ch
FireEyeGeneric.mg.3497f1ea0ea4a4d3
EmsisoftGen:Variant.Razy.463695 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor/SdBot.mgk
WebrootW32.Malware.Heur
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.48C9E9
MicrosoftVirTool:Win32/VBInject.UG
ArcabitTrojan.Razy.D7134F
AegisLabWorm.Win32.Ngrbot.lmdM
ZoneAlarmTrojan-Ransom.Win32.Blocker.jftg
GDataGen:Variant.Razy.463695
McAfeeGenericR-EAA!3497F1EA0EA4
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.Blocker
MalwarebytesMalware.AI.3517544410
PandaTrj/CI.A
RisingTrojan.Win32.VBCode.ckr (CLASSIC)
YandexTrojan.GenAsa!6L+BjrPC27w
IkarusTrojan.Win32.Ircbrute
MaxSecureTrojan.Malware.2355663.susgen
FortinetW32/Refroso.AGEA!tr
AVGWin32:VB-TQE [Trj]
Paloaltogeneric.ml

How to remove Razy.463695?

Razy.463695 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment