Malware

Razy.549032 malicious file

Malware Removal

The Razy.549032 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.549032 virus can do?

  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Network activity detected but not expressed in API logs

How to determine Razy.549032?


File Info:

crc32: D405266D
md5: 34cf933fd6b006dc091c8ce3b04fcb62
name: 41ae627adf9c01cb27c63d4f4dcd1f50a8932799c11d6b8b01.exe
sha1: 4718a503cc0f9e36346109e42b8d67eb75740603
sha256: fcf43cf8fcb59ce532e20ca629883e8f0d7b0fe20f8657786eff703e915d7399
sha512: c9d0c5ea1c8b7865aeaf5791a5daffc5748c787eb25b6951bc965791487299e9ccb2cd8bf2cd1706829a78899cef28ac4c526d0d2447da0a0d119c9ebc3092a0
ssdeep: 98304:TOicS+9m97wwFnw+zmSLRY1vDU1LCAv0SRpNuh6XDLzVdUI9noVgUicWp:TOiNr7fi+zma2U1LXvhRuh6fpd1nYgU
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Razy.549032 also known as:

BkavHW32.Packed.
MicroWorld-eScanGen:Variant.Razy.549032
FireEyeGeneric.mg.34cf933fd6b006dc
Qihoo-360Win32/Trojan.f8f
McAfeeArtemis!34CF933FD6B0
CylanceUnsafe
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Razy.549032
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.fd6b00
TrendMicroTROJ_GEN.R01FC0DBB20
BitDefenderThetaGen:NN.ZexaF.34090.@JW@a4f!Mhai
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
GDataGen:Variant.Razy.549032
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/AutoKMS.75a7c79b
NANO-AntivirusTrojan.Win32.Razy.haegdk
ViRobotTrojan.Win32.Z.Razy.6013952
RisingTrojan.Crypto!8.364 (CLOUD)
Ad-AwareGen:Variant.Razy.549032
SophosMal/Generic-S
ComodoMalware@#1ijc6pzqebyts
F-SecureTrojan.TR/Crypt.ZPACK.Gen
VIPRELooksLike.Win32.Malware!A (v)
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Razy.549032 (B)
IkarusTrojan.Win32.VMProtect
WebrootW32.Trojan.Gen
AviraTR/Crypt.ZPACK.Gen
Endgamemalicious (high confidence)
ArcabitTrojan.Razy.D860A8
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/AutoKMS
AhnLab-V3Trojan/Win32.RL_Generic.R267867
Acronissuspicious
ALYacGen:Variant.Razy.549032
MAXmalware (ai score=85)
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Packed.VMProtect.HR
TrendMicro-HouseCallTROJ_GEN.R01FC0DBB20
TencentWin32.Packed.Vmprotect.Lkxz
SentinelOneDFI – Malicious PE
FortinetRiskware/VMProtectPacked
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Razy.549032?

Razy.549032 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment