Malware

About “Razy.578992” infection

Malware Removal

The Razy.578992 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.578992 virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Attempts to identify installed AV products by installation directory
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Razy.578992?


File Info:

crc32: 0BB0A344
md5: 05a1fe22a53e15a054b2a806b7e61f64
name: cw-hack-v273-864254fb.exe
sha1: 7a8113a68d7ab55e79974ca181604ea9a367da7e
sha256: 5a82b7668156190025042d012c9efcc655ec6835013ecf0a7c0b44ecd0764dfc
sha512: 2b52c9c42ed582aacd6750c3c6c53d1a6aac75a0fc772a8aa6bc7ddbf4d2944fb6d4163837af32fea307b104b6847af5c1b336b74debcc8600dcd08e3e3059f9
ssdeep: 98304:JPtQr84MbFb7YZ0AYxBihYjvZ1WiZNwEclvcYjADBBdyAb:B7jAnYjvZ1bZNw9ldjwyK
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

FileVersion: 7.2
CompanyName: TrueCrypt Foundation
LegalTrademarks: TrueCrypt
ProductName: TrueCrypt
ProductVersion: 7.2
FileDescription: TrueCrypt Setup
OriginalFilename: TrueCrypt Setup.exe
Translation: 0x0409 0x04b0

Razy.578992 also known as:

BkavHW32.Packed.
DrWebTrojan.DownLoader30.42937
MicroWorld-eScanGen:Variant.Razy.578992
FireEyeGeneric.mg.05a1fe22a53e15a0
Qihoo-360Win32/Trojan.cb2
McAfeeArtemis!05A1FE22A53E
CylanceUnsafe
K7AntiVirusTrojan ( 0055b05a1 )
BitDefenderGen:Variant.Razy.578992
K7GWTrojan ( 0055b05a1 )
BitDefenderThetaGen:NN.ZexaF.34106.@F2@aez5y!ei
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
GDataGen:Variant.Razy.578992
KasperskyHEUR:Trojan.Win32.Ekstak.pef
AlibabaPacked:Win32/VMProtect.bf790731
RisingTrojan.Ekstak!8.EB77 (CLOUD)
Ad-AwareGen:Variant.Razy.578992
SophosMal/Generic-S
ComodoMalware@#358kg8v33jb3m
F-SecureTrojan.TR/Ekstak.rcdjl
McAfee-GW-EditionArtemis!Trojan
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Razy.578992 (B)
IkarusTrojan.Win32.VMProtect
WebrootW32.Trojan.Gen
AviraTR/Ekstak.rcdjl
Endgamemalicious (high confidence)
ArcabitTrojan.Razy.D8D5B0
ZoneAlarmHEUR:Trojan.Win32.Ekstak.pef
MicrosoftTrojan:Win32/Wacatac.C!ml
AhnLab-V3PUP/Win32.RL_Generic.R298674
Acronissuspicious
ALYacGen:Variant.Razy.578992
MAXmalware (ai score=80)
MalwarebytesAdware.DownloadAssistant
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Packed.VMProtect.MP
YandexTrojan.VMProtect!
SentinelOneDFI – Malicious PE
eGambitPE.Heur.InvalidSig
FortinetW32/Kryptik.GYDW!tr
AVGWin32:TrojanX-gen [Trj]

How to remove Razy.578992?

Razy.578992 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment