Malware

About “Razy.472965 (B)” infection

Malware Removal

The Razy.472965 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.472965 (B) virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Razy.472965 (B)?


File Info:

crc32: FA00DCF4
md5: 9367a61d41586260117e0638ee5c3e87
name: 9367A61D41586260117E0638EE5C3E87.mlw
sha1: 710a7f57080f6ea9b515cdb504e8ba8c3b33b930
sha256: 159d1d55c63884c22856ae5b2f6ded5027a9e800d87ef5b87306466906900545
sha512: 7769fa5ef7a5e9a562dfc0fca36faa39148b5a71e8dc20979ef3ceeb20b68a8a406af6a7cc350b1b0fba623b2eb7485b361097e013c0bb0376d008ee35d30c67
ssdeep: 1536:CFVtbqmYap7ilLb8d1NKJ6cF0HPXYEMm:CFLbqnmik1NQbsXY
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

Razy.472965 (B) also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.472965
FireEyeGeneric.mg.9367a61d41586260
Qihoo-360HEUR/QVM03.0.2007.Malware.Gen
McAfeeGenericRXEK-KS!9367A61D4158
CylanceUnsafe
K7AntiVirusTrojan ( 700000121 )
BitDefenderGen:Variant.Razy.472965
K7GWTrojan ( 700000121 )
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/Revetrat.A.gen!Eldorado
SymantecTrojan.Revetrat
APEXMalicious
ClamAVWin.Trojan.RevengeRat-6344273-0
KasperskyHEUR:Trojan.Win32.RRAT.gen
Ad-AwareGen:Variant.Razy.472965
EmsisoftGen:Variant.Razy.472965 (B)
ComodoTrojWare.MSIL.Revetrat.A@7osjcj
F-SecureTrojan.TR/ATRAPS.Gen
DrWebBackDoor.RevetRat.2
TrendMicroBKDR_REVET.SM
McAfee-GW-EditionBehavesLike.Win32.Generic.cz
SophosML/PE-A + Mal/Revet-A
SentinelOneStatic AI – Malicious PE
AviraTR/ATRAPS.Gen
MAXmalware (ai score=83)
MicrosoftBackdoor:MSIL/RevengeRat.GA!MTB
ArcabitTrojan.Razy.D73785
ZoneAlarmHEUR:Trojan.Win32.RRAT.gen
GDataGen:Variant.Razy.472965
CynetMalicious (score: 90)
BitDefenderThetaGen:NN.ZemsilF.34700.lmW@aK8vlXb
ALYacGen:Variant.Razy.472965
MalwarebytesBackdoor.RevengeRAT
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Agent.APN
TrendMicro-HouseCallBKDR_REVET.SM
RisingBackdoor.Revetrat!1.B8DA (CLASSIC)
IkarusBackdoor-Rat.Revenge
eGambitTrojan.Generic
FortinetMSIL/RevengeRat.APN!tr
AVGWin32:MalwareX-gen [Trj]
Cybereasonmalicious.d41586
AvastWin32:MalwareX-gen [Trj]

How to remove Razy.472965 (B)?

Razy.472965 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment