Malware

How to remove “Razy.628496 (B)”?

Malware Removal

The Razy.628496 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.628496 (B) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • A scripting utility was executed
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Razy.628496 (B)?


File Info:

crc32: D4A3958B
md5: c09a3884af4f15b8c84fd7780a33ad21
name: C09A3884AF4F15B8C84FD7780A33AD21.mlw
sha1: 776f6a72243ddd6e78df6d2bc20298d99ac483ea
sha256: 7e2df5cc5af70da7aebf1285a7ad9956766ded3aab658520bf93d4d5b85f1159
sha512: 0265297b7044053f299dce05309871cf3e3ea109f195ea9807711d8bb6eec0210f9f3ab0e48d4c2b56e2c4c2be4992dfb2071a660298368f263f6143f8cb967d
ssdeep: 12288:Q6Lt/23z4EEKqtX+t498bwkpLHoBvXZYTK:Q6/23GKqXkfIFXGTK
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Razy.628496 (B) also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.628496
FireEyeGeneric.mg.c09a3884af4f15b8
CAT-QuickHealTrojan.MSIL
McAfeeArtemis!C09A3884AF4F
BitDefenderGen:Variant.Razy.628496
Cybereasonmalicious.2243dd
TrendMicroTrojan.MSIL.DROPPER.AQ
CyrenW32/Trojan.RCGH-8695
SymantecTrojan.Gen.2
APEXMalicious
ClamAVWin.Packed.Emotet-9790742-0
KasperskyHEUR:Trojan.MSIL.Dnoper.gen
NANO-AntivirusTrojan.Win32.Dnoper.iariay
ComodoMalware@#3lz7v6qjpdgb5
F-SecureTrojan.TR/Dropper.Gen2
DrWebTrojan.Starter.2890
InvinceaGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.Backdoor.gc
EmsisoftGen:Variant.Razy.628496 (B)
IkarusTrojan-Dropper.MSIL.Agent
AviraTR/Dropper.Gen2
MicrosoftTrojan:Win32/Wacatac.D7!ml
ArcabitTrojan.Razy.D99710
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Razy.628496
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.RL_Generic.R355449
BitDefenderThetaGen:NN.ZemsilF.34590.Gm0@a4Pthw
MAXmalware (ai score=81)
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.MalPack
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.DPV
TrendMicro-HouseCallTrojan.MSIL.DROPPER.AQ
YandexTrojan.Igent.bUF7gv.4
SentinelOneStatic AI – Malicious SFX
FortinetW32/Dnoper.DPV!tr
AVGWin32:RATX-gen [Trj]
AvastWin32:RATX-gen [Trj]
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Razy.628496 (B)?

Razy.628496 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment