Malware

Razy.630228 removal tips

Malware Removal

The Razy.630228 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.630228 virus can do?

  • Drops a binary and executes it
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

How to determine Razy.630228?


File Info:

crc32: 5E559C31
md5: cd8ef9620a6b9ca18a6647d977398606
name: client.exe
sha1: 7d9088ec691191f0f681c9d612957e643cc0ad1f
sha256: a356d92ade4d8d537ea6dfabe765d4cd2ff851faae1d4551b91e50b47aac216f
sha512: f79cf96ef5c101d58c9980db7085a89364946410a76057c932159b76f9f75f2dd86ae74e1fae04cd2fae40e5e43e97fad72025f24e8ca74ed4cd38107f50a10a
ssdeep: 12288:PM/pdm3LuEH5GzYVGBCMBfh6rSWcdFpzhg:GUTGzsGJJorfQhhg
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Razy.630228 also known as:

DrWebTrojan.MulDrop11.52446
MicroWorld-eScanGen:Variant.Razy.630228
FireEyeGeneric.mg.cd8ef9620a6b9ca1
CAT-QuickHealTrojan.ClipBanker
Qihoo-360Win32/Trojan.fe8
ALYacGen:Variant.Razy.630228
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 0054c4a01 )
BitDefenderGen:Variant.Razy.630228
K7GWTrojan ( 0054c4a01 )
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34108.AuW@au517Kp
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
GDataGen:Variant.Razy.630228
KasperskyTrojan-Banker.Win32.ClipBanker.krw
AlibabaTrojanBanker:Win32/ClipBanker.376fab46
NANO-AntivirusTrojan.Win32.ClipBanker.hhkyqp
ViRobotTrojan.Win32.Z.Clipbanker.432128
AegisLabTrojan.Win32.ClipBanker.7!c
TencentWin32.Trojan-banker.Clipbanker.Tbis
Ad-AwareGen:Variant.Razy.630228
SophosMal/Generic-S
ComodoMalware@#31uzzbbfzkjej
F-SecureHeuristic.HEUR/AGEN.1117023
ZillyaTrojan.ClipBanker.Win32.3787
TrendMicroTROJ_GEN.R011C0PDL20
McAfee-GW-EditionBehavesLike.Win32.Generic.gh
EmsisoftGen:Variant.Razy.630228 (B)
SentinelOneDFI – Suspicious PE
CyrenW32/Trojan.HWTT-6293
JiangminTrojan.Banker.ClipBanker.aee
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1117023
Antiy-AVLTrojan[Banker]/Win32.ClipBanker
Endgamemalicious (high confidence)
ArcabitTrojan.Razy.D99DD4
ZoneAlarmTrojan-Banker.Win32.ClipBanker.krw
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Malware/Win32.Generic.C4062956
McAfeeRDN/PWS-Banker
MAXmalware (ai score=80)
VBA32BScope.TrojanDropper.Scrop
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/ClipBanker.IR
TrendMicro-HouseCallTROJ_GEN.R011C0PDL20
RisingTrojan.ClipBanker!8.5FB (CLOUD)
YandexTrojan.ClipBanker!
IkarusTrojan.Win32.Clipbanker
FortinetW32/ClipBanker.IR!tr
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
MaxSecureTrojan.Malware.1728101.susgen

How to remove Razy.630228?

Razy.630228 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment