Malware

About “Razy.645028” infection

Malware Removal

The Razy.645028 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.645028 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
skypevpn.zapto.org

How to determine Razy.645028?


File Info:

crc32: 3D296777
md5: af6b915e12754e54ca02e67e59842f2a
name: AF6B915E12754E54CA02E67E59842F2A.mlw
sha1: 283b3a0a362cb73865a745b8e8272b0112db870a
sha256: 8d8ff21a36e640a39e6362aa318d019e53d5616c37349d6bd7c9008992eb4eb4
sha512: 3271c59851041b88026ee61a6e6495ad28857248f1b4ca7d4b18e1b1ac637d109e078f2b26d14cad48de8467abc2c8b274712366dfbe34cee94742e790b7ccd6
ssdeep: 1536:MZgyb1mUJnr3SIVDUhScBeJ03Go4IhSAZ/HmHR:KgyxmqjDUYcBeeGmhSA
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

Razy.645028 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.645028
FireEyeGeneric.mg.af6b915e12754e54
CAT-QuickHealTrojan.MSIL
ALYacGen:Variant.Razy.645028
CylanceUnsafe
VIPREBackdoor.MSIL.Bladabindi.ab (v)
AegisLabTrojan.MSIL.Agent.4!c
SangforMalware
K7AntiVirusTrojan ( 004b8b3f1 )
BitDefenderGen:Variant.Razy.645028
K7GWTrojan ( 004b8b3f1 )
CrowdStrikewin/malicious_confidence_90% (D)
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan.MSIL.Agent.dkci
AlibabaTrojan:MSIL/Injector.b999e074
Ad-AwareGen:Variant.Razy.645028
EmsisoftGen:Variant.Razy.645028 (B)
ComodoTrojWare.MSIL.Injector.GPA@53p4eh
F-SecureTrojan.TR/Dropper.MSIL.Gen
DrWebBackDoor.Bladabindi.1393
TrendMicroTROJ_GEN.R002C0WB121
McAfee-GW-EditionRDN/Generic.rp
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.MSIL.Gen
eGambitUnsafe.AI_Score_99%
MicrosoftBackdoor:Win32/Bladabindi!ml
ArcabitTrojan.Razy.D9D7A4
ZoneAlarmHEUR:Trojan.MSIL.Generic
GDataGen:Variant.Razy.645028
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.C4319186
McAfeeRDN/Generic.rp
MAXmalware (ai score=86)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Injector.CCM
TrendMicro-HouseCallTROJ_GEN.R002C0WB121
TencentMsil.Trojan.Agent.Lplj
IkarusTrojan.MSIL.Injector
FortinetMSIL/Injector.CCM!tr
BitDefenderThetaGen:NN.ZemsilF.34804.emW@a8!7hul
AVGWin32:Trojan-gen
Cybereasonmalicious.e12754
Paloaltogeneric.ml
Qihoo-360Win32/TrojanDropper.Generic.HwMAaH8A

How to remove Razy.645028?

Razy.645028 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment