Malware

Razy.506371 removal guide

Malware Removal

The Razy.506371 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.506371 virus can do?

  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Razy.506371?


File Info:

crc32: FEA93020
md5: 1f2c2e2b5dd5870436fb8d21e6cf1a3b
name: 1F2C2E2B5DD5870436FB8D21E6CF1A3B.mlw
sha1: fcff6bc87527c25a21505c713e047df5fcfd6595
sha256: 2fa85d68221954e7e2db645822bb5b76470c91f03409f8fd16b76c9e1f84822b
sha512: 43b450b09ef4f238eef882bf34e309f9facaf63fc2f09f352a676b2613dd5182c37e74835aad045281e3b8c98d1e33b2aed36788176bf46ed92eec0971efa7de
ssdeep: 12288:653AsOpvQPNTkDKS594nUAz6GqSy86J/Roga:IwFA+KI9476z
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: dwm.exe
FileVersion: 10.0.10240.16384 (th1.150709-1700)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 10.0.10240.16384
FileDescription: Desktop Window Manager
OriginalFilename: dwm.exe
Translation: 0x0409 0x04b0

Razy.506371 also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.506371
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
Cybereasonmalicious.b5dd58
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.JB
APEXMalicious
AvastMSIL:Agent-BMU [Trj]
ClamAVWin.Packed.njRAT-7752919-1
KasperskyHEUR:Backdoor.MSIL.Bladabindi.gen
BitDefenderGen:Variant.Razy.506371
MicroWorld-eScanGen:Variant.Razy.506371
Ad-AwareGen:Variant.Razy.506371
SophosML/PE-A
ComodoTrojWare.MSIL.Zapchast.IW@7k7mpi
BitDefenderThetaGen:NN.ZemsilF.34686.Cm0@aiBWKadi
FireEyeGeneric.mg.1f2c2e2b5dd58704
EmsisoftGen:Variant.Razy.506371 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1127783
eGambitUnsafe.AI_Score_99%
MicrosoftBackdoor:MSIL/Bladabindi
ArcabitTrojan.Razy.D7BA03
ZoneAlarmHEUR:Backdoor.MSIL.Bladabindi.gen
GDataGen:Variant.Razy.506371
AhnLab-V3Trojan/Win32.Bladabindi.C2917319
MAXmalware (ai score=80)
MalwarebytesBackdoor.Bladabindi
FortinetMSIL/Kryptik.B033!tr
AVGMSIL:Agent-BMU [Trj]

How to remove Razy.506371?

Razy.506371 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment