Malware

Razy.620138 removal instruction

Malware Removal

The Razy.620138 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.620138 virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Razy.620138?


File Info:

crc32: 8C6EC968
md5: 9e5200a1a8e29f05576e0cf05abd0dc1
name: xxx.exe
sha1: 35e5ddac320b0cabb2c76baab5fe248bcfe606a5
sha256: 7c9b85ed3d08d9cf1ef00d3d4f12385a23a121892b08b197ed5ccf2a49331c42
sha512: 955eda51f76b6fb22ea86c98fafd2b98cbfca315a0ee4a7c4d014c1ba64935babe1dca3d04e900a22df253492d299070265a518639e5a7c4d61f96278cb6a1f4
ssdeep: 384:Ga5uLOi9QqGjQiqopRjF4yh0lZGTa2JhBrE7Ve4w74K7t6pR8bZSWwlW:N4DAjXqo/yyh0+hhBrwVeL74K7MpR8S
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: PresentationFramework.Aero.dll
FileVersion: 4.0.30319.18402 built by: FX451RTMGREL
CompanyName: Microsoft Corporation
PrivateBuild: DDBLD287
Comments: Flavor=Retail
ProductName: Microsoftxae .NET Framework
ProductVersion: 4.0.30319.18402
FileDescription: PresentationFramework.Aero.dll
OriginalFilename: PresentationFramework.Aero.dll
Translation: 0x0409 0x04b0

Razy.620138 also known as:

MicroWorld-eScanGen:Variant.Razy.620138
FireEyeGen:Variant.Razy.620138
Qihoo-360Generic/Trojan.6f3
McAfeeArtemis!9E5200A1A8E2
CylanceUnsafe
AegisLabTrojan.MSIL.Seraph.a!c
K7AntiVirusTrojan-Downloader ( 00561bae1 )
BitDefenderGen:Variant.Razy.620138
K7GWTrojan-Downloader ( 00561bae1 )
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:DropperX-gen [Drp]
GDataGen:Variant.Razy.620138
KasperskyHEUR:Trojan-Downloader.MSIL.Seraph.gen
AlibabaTrojanDownloader:MSIL/Seraph.ff569751
TencentMsil.Trojan-downloader.Agent.Hvss
EmsisoftGen:Variant.Razy.620138 (B)
F-SecureHeuristic.HEUR/AGEN.1046951
DrWebTrojan.Siggen9.22016
TrendMicroTROJ_GEN.R002C0PCI20
McAfee-GW-EditionDownloader-FBXL!9E5200A1A8E2
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
IkarusTrojan-Downloader.MSIL.Agent
AviraHEUR/AGEN.1046951
MAXmalware (ai score=88)
ArcabitTrojan.Razy.D9766A
ZoneAlarmHEUR:Trojan-Downloader.MSIL.Seraph.gen
MicrosoftTrojan:Win32/Wacatac.C!ml
ALYacGen:Variant.Razy.620138
Ad-AwareGen:Variant.Razy.620138
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.GAO
TrendMicro-HouseCallTROJ_GEN.R002C0PCI20
RisingDownloader.Agent!8.B23 (CLOUD)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_64%
FortinetMSIL/Agent.GAL!tr
BitDefenderThetaGen:NN.ZemsilF.34100.bm0@aifq3Pdi
AVGWin32:DropperX-gen [Drp]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Razy.620138?

Razy.620138 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment