Malware

Razy.549442 (B) (file analysis)

Malware Removal

The Razy.549442 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.549442 (B) virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Razy.549442 (B)?


File Info:

crc32: 0EC365F6
md5: c087beae29e1b438c3636526ed404db9
name: C087BEAE29E1B438C3636526ED404DB9.mlw
sha1: 0fd8692c6ded655a8601be9e8027cd130b806724
sha256: 04e34aad6466f6bfbf51a502632f94e8b2af089740ac1301f4b6443c026c35ad
sha512: 13483c3f6c4f2024f4d406c3edd31f440169086324f07f591f624dcda6c0d5f6cc84d95a39fcb196ad813a3b4e40fd3b04aff2f70a663cfc0786ec0fa84974bb
ssdeep: 6144:cLQmhTECuWZm4G+7PJQ4Hwqxy0O/zZhXn/q:GOrZhXnC
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright 2021 Essential MFs
Assembly Version: 6.9.0.0
InternalName: DiSCO.exe
FileVersion: 6.9.0.0
ProductName: DiSCO
ProductVersion: 6.9.0.0
FileDescription: DiSCO
OriginalFilename: DiSCO.exe

Razy.549442 (B) also known as:

K7AntiVirusTrojan-Downloader ( 005258661 )
Elasticmalicious (high confidence)
DrWebTrojan.KillProc2.11418
CynetMalicious (score: 99)
ALYacGen:Variant.Razy.549442
CylanceUnsafe
SangforTrojan.MSIL.Xegumumune.gen
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojanSpy:MSIL/Xegumumune.26ddfa89
K7GWTrojan-Downloader ( 005258661 )
Cybereasonmalicious.e29e1b
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDownloader.Small.BLY
APEXMalicious
AvastWin32:RATX-gen [Trj]
KasperskyHEUR:Trojan-Spy.MSIL.Xegumumune.gen
BitDefenderGen:Variant.Razy.549442
MicroWorld-eScanGen:Variant.Razy.549442
TencentMsil.Trojan-spy.Xegumumune.Swkl
Ad-AwareGen:Variant.Razy.549442
SophosGeneric ML PUA (PUA)
BitDefenderThetaGen:NN.ZemsilCO.34692.xm0@aWmhnUi
TrendMicroTROJ_GEN.R002C0PER21
McAfee-GW-EditionBehavesLike.Win32.Packed.ft
FireEyeGeneric.mg.c087beae29e1b438
EmsisoftGen:Variant.Razy.549442 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1121965
eGambitUnsafe.AI_Score_86%
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Razy.549442
AhnLab-V3Trojan/Win32.Kryptik.C3320430
McAfeeGenericRXOD-WL!C087BEAE29E1
MAXmalware (ai score=86)
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0PER21
RisingSpyware.Xegumumune!8.10962 (CLOUD)
IkarusTrojan-Dropper.MSIL.Agent
FortinetMSIL/CoinMiner.DMA!tr
AVGWin32:RATX-gen [Trj]
Paloaltogeneric.ml

How to remove Razy.549442 (B)?

Razy.549442 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment