Malware

Razy.577898 (B) (file analysis)

Malware Removal

The Razy.577898 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.577898 (B) virus can do?

  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Razy.577898 (B)?


File Info:

crc32: EF44B57B
md5: 6a726313292a89ea4055a5f8f196458d
name: bnt.exe
sha1: 1de824850b505070e3a3efb2f6360383256f8c1e
sha256: 7ae2e48b9213f15e6217abf256e4c23d9548e18bf35678d24b63afb1e45d31c8
sha512: 56c24360708fb8fa71658744b8bc66d56f406d309de104c8590834ec82d0e40953ab04075c96c90219cbf76dd6a3bd8461c34e5f4ad71a0221e0ff892b72337d
ssdeep: 6144:njtWa8H69CizsXoKBxppXU29rs52dey7HdEz5y5a/fGejlNwDKb:nQH6YpBxppD9rsw1OMe
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright (c) 2003-2015 Apple Inc.
Assembly Version: 3.1.0.0
InternalName: hIyFBDoAfZmqYPQqHZTqKIPpScrwJobWnYnN.exe
FileVersion: 3.1.0
CompanyName: Apple Inc.
Comments: Bonjour Service
ProductName: Bonjour
ProductVersion: 3.1.0
FileDescription: mDNSResponder.exe
OriginalFilename: hIyFBDoAfZmqYPQqHZTqKIPpScrwJobWnYnN.exe

Razy.577898 (B) also known as:

MicroWorld-eScanGen:Variant.Razy.577898
FireEyeGeneric.mg.6a726313292a89ea
Qihoo-360Generic/Trojan.PSW.a32
McAfeeGenericRXJM-ZZ!6A726313292A
CylanceUnsafe
SangforMalware
K7AntiVirusSpyware ( 004bf53c1 )
BitDefenderGen:Variant.Razy.577898
K7GWSpyware ( 004bf53c1 )
Cybereasonmalicious.50b505
Invinceaheuristic
F-ProtW32/Azorult.D.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Razy-7426372-0
GDataGen:Variant.Razy.577898
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.a
AegisLabTrojan.MSIL.Agensla.i!c
RisingSpyware.AgentTesla!1.B864 (CLOUD)
Ad-AwareGen:Variant.Razy.577898
SophosMal/Generic-S
F-SecureTrojan.TR/Dropper.Gen
TrendMicroBackdoor.MSIL.REMCOS.THABBBO
McAfee-GW-EditionBehavesLike.Win32.Trojan.dh
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Razy.577898 (B)
SentinelOneDFI – Malicious PE
CyrenW32/Azorult.D.gen!Eldorado
WebrootW32.Trojan.Gen
AviraTR/Dropper.Gen
Endgamemalicious (high confidence)
ArcabitTrojan.Razy.D8D16A
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.a
MicrosoftBackdoor:MSIL/Remcos!MTB
AhnLab-V3Trojan/Win32.AgentTesla.C3468286
ALYacGen:Variant.Razy.577898
MAXmalware (ai score=86)
MalwarebytesSpyware.AgentTesla.MSIL.Generic
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Spy.Agent.AES
TrendMicro-HouseCallBackdoor.MSIL.REMCOS.THABBBO
TencentWin32.Trojan.Generic.Wqde
IkarusTrojan.MSIL.Spy
eGambitUnsafe.AI_Score_99%
FortinetMSIL/Spy.AES!tr
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Razy.577898 (B)?

Razy.577898 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment