Malware

What is “Razy.525651 (B)”?

Malware Removal

The Razy.525651 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.525651 (B) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • A scripting utility was executed
  • Attempts to stop active services
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Razy.525651 (B)?


File Info:

crc32: 41565D16
md5: 67b0071df0425f3453f429576ebc711f
name: tmpw9a1l369
sha1: 43e62a9fc4d15560b04d2d43626a40a29f433b24
sha256: fffc6d0f945e951e9c775e1cd50817c08b6ae521a0b891135d1dbd914da4198a
sha512: 72b54f9b1be6171d70bf4c200481579f1b13e8226309dbfbd09d23ec057f0634b04d03d283279ebe54c1298606daf677d2dd37d941834684af59726143fc307b
ssdeep: 1536:/DMcoFQf0U4u//dpkDM5Rw8IP3NHpwOqJICS4A9Oqlygqfc66DP5Ctwe:euDkD+I3NJFqqlnTP5Ctw
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Razy.525651 (B) also known as:

BkavW32.AIDetectVM.malware2
DrWebTrojan.Encoder.28004
MicroWorld-eScanGen:Variant.Razy.525651
FireEyeGeneric.mg.67b0071df0425f34
McAfeeSodinokibi!67B0071DF042
CylanceUnsafe
K7GWTrojan ( 0054d99c1 )
K7AntiVirusTrojan ( 0054d99c1 )
ArcabitTrojan.Razy.D80553
Invinceaheuristic
BitDefenderThetaAI:Packer.E7632E1F1E
F-ProtW32/Kryptik.AKW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.Sodinokibi.B
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Ransomware.Sodinokibi-7013612-0
KasperskyHEUR:Trojan-Ransom.Win32.Gen.gen
BitDefenderGen:Variant.Razy.525651
NANO-AntivirusVirus.Win32.Gen.ccmw
RisingRansom.Sodin!8.10CD8 (RDMK:cmRtazpNs75r8WmkD5okk/u6KSL7)
Ad-AwareGen:Variant.Razy.525651
F-SecureTrojan.TR/Crypt.XPACK.Gen
TrendMicroRansom.Win32.SODINOKIB.SMTH
McAfee-GW-EditionSodinokibi!67B0071DF042
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Razy.525651 (B)
IkarusTrojan-Ransom.Sodinokibi
CyrenW32/Kryptik.AKW.gen!Eldorado
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=83)
Antiy-AVLTrojan[Ransom]/Win32.Gen
MicrosoftRansom:Win32/Sodinokibi.DSB!MTB
Endgamemalicious (high confidence)
ZoneAlarmHEUR:Trojan-Ransom.Win32.Gen.gen
GDataGen:Variant.Razy.525651
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.RL_Ransom.R290570
Acronissuspicious
VBA32BScope.Trojan.DelShad
ALYacGen:Variant.Razy.525651
TrendMicro-HouseCallRansom.Win32.SODINOKIB.SMTH
TencentMalware.Win32.Gencirc.119979e5
YandexTrojan.Filecoder!i8F89yM0sus
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_82%
FortinetW32/Sodinokibi.B!tr.ransom
AVGWin32:Trojan-gen
Cybereasonmalicious.df0425
PandaTrj/GdSda.A
Qihoo-360HEUR/QVM20.1.1FBF.Malware.Gen

How to remove Razy.525651 (B)?

Razy.525651 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment