Malware

Should I remove “Razy.645622 (B)”?

Malware Removal

The Razy.645622 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.645622 (B) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Czech
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests credentials from local FTP client softwares
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
ip-api.com
sdfvbshgdvf.pw

How to determine Razy.645622 (B)?


File Info:

crc32: AC008A0E
md5: f6af5a322ed194d8bcf6fcb782cbac0e
name: F6AF5A322ED194D8BCF6FCB782CBAC0E.mlw
sha1: 7b701fcc8ae14d69e9836e83740468085fac25fd
sha256: cdfce998e859a0f7566a57c50883ab96aa3ee35b797761cbfc7958fdb85bb2b3
sha512: fe678fde4b8e7486397d3a5c8e879869da9292589e454c10f9a0f884cca6209e3e06b60b699a61b4baa1848b7b7dc9f355e6ca497f31728b58233743df397e67
ssdeep: 12288:RvUamtDbtsU6dn9cPlCa3IMqBxoyehjQrBmXbyQGP1qMbtAV9E7y:RvxNU6J9cPwa3IvxoyWjBXufNqMbt6m
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2017, caxacpgola
FileVersion: 8.4.3.12

Razy.645622 (B) also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Chapak.4!c
Elasticmalicious (high confidence)
ALYacGen:Variant.Razy.645622
MalwarebytesTrojan.MalPack
ZillyaTrojan.GenericKD.Win32.147806
SangforRansom.Win32.Gandcrab_147.se2
CrowdStrikewin/malicious_confidence_80% (D)
BitDefenderGen:Variant.Razy.645622
K7GWTrojan ( 0053a3311 )
K7AntiVirusTrojan ( 0053a3311 )
BitDefenderThetaGen:NN.ZexaF.34126.Su0@aO7gVxhG
CyrenW32/GandCrypt.C.gen!Eldorado
ESET-NOD32a variant of Win32/Kryptik.GJRW
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Chapak.anvb
AlibabaTrojan:Win32/Chapak.810b0991
NANO-AntivirusTrojan.Win32.Chapak.fhmpno
ViRobotTrojan.Win32.U.GandCrab.311296.A
MicroWorld-eScanGen:Variant.Razy.645622
TencentWin32.Trojan.Chapak.Eehj
Ad-AwareGen:Variant.Razy.645622
SophosMal/Generic-S + Mal/GandCrab-G
ComodoTrojWare.Win32.Crypt.ACE@7wfy01
DrWebTrojan.PWS.Panda.13495
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Trojan.bc
FireEyeGeneric.mg.f6af5a322ed194d8
EmsisoftGen:Variant.Razy.645622 (B)
JiangminTrojan.Generic.blcud
AviraHEUR/AGEN.1103322
Antiy-AVLTrojan/Generic.ASMalwS.27A8F47
GDataWin32.Trojan-Ransom.GandCrab.N
AhnLab-V3Win-Trojan/MalPe34.Suspicious.X2029
Acronissuspicious
VBA32Trojan.Fuerboos
MAXmalware (ai score=100)
TrendMicro-HouseCallPossible_HPGen-31
RisingMalware.Obscure/Heur!1.A89E (CLASSIC)
YandexTrojan.GenAsa!fmIQGcesT70
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.GKJF!tr
PandaTrj/GdSda.A

How to remove Razy.645622 (B)?

Razy.645622 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment