Malware

Razy.640849 removal guide

Malware Removal

The Razy.640849 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.640849 virus can do?

  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Razy.640849?


File Info:

crc32: 74B60E71
md5: 705d23c84c5c0e8815650cfaa73d8f76
name: tmplwwbjrsc
sha1: e44deb479efd2f5404667c146e3083b4b1b051fd
sha256: 916aeaa51050f25dbbcefc1be1820457e1d9d755a44d2d0cf62155f75c54127c
sha512: 7130c3e4621c9ac3e33fda224d138f65bf1049bf86f7f754e128276d23d53e9887751c37798fef93e51b540f1acf5fd9af4f1e13dd49b9aa17586b531f36b3b1
ssdeep: 1536:NgHU9d853VGa9q3QtQ0LC3x4b21JciF7eJHW0:Ng03bRJ0W3x4b2cCCRf
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: Client-0.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: Client-0.exe

Razy.640849 also known as:

MicroWorld-eScanGen:Variant.Razy.640849
FireEyeGeneric.mg.705d23c84c5c0e88
CAT-QuickHealTrojan.Multi
McAfeeRDN/Ransom
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.14739
SangforMalware
K7AntiVirusTrojan ( 0055befa1 )
AlibabaRansom:MSIL/Hakbit.38e698a8
K7GWTrojan ( 0055befa1 )
Cybereasonmalicious.79efd2
TrendMicroRansom.MSIL.HAKBIT.C
BitDefenderThetaGen:NN.ZemsilF.34128.dm0@aGyGi3m
CyrenW32/Trojan.TEXY-2944
SymantecDownloader
TrendMicro-HouseCallRansom.MSIL.HAKBIT.C
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.MSIL.DelShad.gen
BitDefenderGen:Variant.Razy.640849
Paloaltogeneric.ml
AegisLabTrojan.Multi.Generic.4!c
RisingRansom.Genasom!8.293 (CLOUD)
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Razy.640849 (B)
ComodoMalware@#13g3yjvq821m3
F-SecureTrojan.TR/Ransom.kofuv
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.qh
SentinelOneDFI – Malicious PE
SophosMal/Hakbit-A
APEXMalicious
JiangminTrojan.MSIL.ouwb
WebrootW32.Malware.Gen
AviraTR/Ransom.kofuv
MicrosoftRansom:MSIL/Hakbit.SK!MTB
ArcabitTrojan.Razy.D9C751
ViRobotTrojan.Win32.S.Ransom.58880.A
ZoneAlarmHEUR:Trojan.MSIL.DelShad.gen
GDataGen:Variant.Razy.640849
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.FileCoder.C4004143
VBA32TScope.Trojan.MSIL
ALYacTrojan.Ransom.Hakbit
MAXmalware (ai score=100)
Ad-AwareGen:Variant.Razy.640849
MalwarebytesTrojan.Injector
ESET-NOD32a variant of MSIL/Filecoder.Thanos.A
YandexTrojan.Filecoder!9t9qGM5uBH8
IkarusTrojan-Ransom.FileCrypter
eGambitUnsafe.AI_Score_64%
FortinetW32/DelShad.VL!tr.ransom
MaxSecureTrojan.Malware.74133646.susgen
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Generic/HEUR/QVM03.0.5C1C.Malware.Gen

How to remove Razy.640849?

Razy.640849 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment