Malware

Razy.614826 information

Malware Removal

The Razy.614826 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.614826 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Attempts to connect to a dead IP:Port (10 unique times)
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

tntcash.com
i.cdnpark.com
fonts.googleapis.com
fonts.gstatic.com
d1lxhc4jvstzrp.cloudfront.net
js.parkingcrew.net
ocsp.pki.goog
crl.pki.goog
crls.pki.goog

How to determine Razy.614826?


File Info:

crc32: 68A671B3
md5: 76385c93e5cadab9ce5bf6f8580aefe5
name: 76385C93E5CADAB9CE5BF6F8580AEFE5.mlw
sha1: 2db3e809027026aa1df933b4206b88c3521f9b1f
sha256: 1dbd8ace68a8746f186dcdb9751292a42816b04f0c1cc680bcc5a147fc6d7567
sha512: 0a664679c0040c5f3466d7106487f0d9943d22d655c5b7bca38539777346b03d03950ce4e13aabc8eb6a79f429c0e89eea6f8e2d762a1559bb2ebfd35fef3099
ssdeep: 768:RD1iuntIDpzBgXVrJJHnUR/5vPBJ/OvhL0u:T/ntIDpzBgXVrJJHnURBvPBJ/OvZ0u
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
ProductVersion: 1.00
InternalName: clix0r
FileVersion: 1.00
OriginalFilename: clix0r.exe
ProductName: wmplay

Razy.614826 also known as:

BkavW32.AIDetect.malware2
DrWebTrojan.Click3.22183
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.614826
CylanceUnsafe
ZillyaTrojan.VB.Win32.103716
SangforTrojan.Win32.VB.nn
AlibabaTrojanClicker:Win32/ATRAPS.68df3881
Cybereasonmalicious.3e5cad
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Clicker.Win32.VB.nn
BitDefenderGen:Variant.Razy.614826
NANO-AntivirusTrojan.Win32.VB.egnujo
MicroWorld-eScanGen:Variant.Razy.614826
TencentWin32.Trojan.Vb.Agbg
Ad-AwareGen:Variant.Razy.614826
SophosMal/Generic-S
ComodoTrojWare.Win32.TrojanClicker.VB.BP0@1vu5ao
BitDefenderThetaGen:NN.ZevbaF.34266.bm0@aCvZI8ei
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Trojan.mz
FireEyeGeneric.mg.76385c93e5cadab9
EmsisoftGen:Variant.Razy.614826 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanClicker.VB.hyv
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan/Generic.ASMalwS.1014569
KingsoftWin32.Troj.VB.nn.(kcloud)
MicrosoftTrojan:Win32/Occamy.C1D
GDataGen:Variant.Razy.614826
AhnLab-V3Trojan/Win32.VB.R328627
McAfeeArtemis!76385C93E5CA
MAXmalware (ai score=99)
VBA32Trojan.VBRA.03138
PandaTrj/Genetic.gen
YandexTrojan.CL.VB!P90v8CVtVAg
IkarusTrojan.ATRAPS
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VB.OJH!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Razy.614826?

Razy.614826 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment