Malware

About “Razy.649460” infection

Malware Removal

The Razy.649460 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.649460 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Interacts with known DarkComet registry keys
  • Attempts to disable UAC
  • Attempts to modify or disable Security Center warnings
  • Creates known Fynloski/DarkComet mutexes

Related domains:

09068x.ddns.net

How to determine Razy.649460?


File Info:

crc32: 1B3301A8
md5: 1a9c8244681159913d7df3e862f35590
name: 1A9C8244681159913D7DF3E862F35590.mlw
sha1: c9f3557c9628ed0d28961741e10efff3ab27b753
sha256: f8a9c01ab699b42e4831ddcd5940b2b1b1a09d8f2bfcb4c740e08940173952ab
sha512: 534ead2de83ad3f93c21d140647b37366698f2f854a616678114f957307d90e42ed928ae013938e39491fac82c30f903529dc2f1973e25cd76c80037a3da4d90
ssdeep: 24576:Uzh9F1TsBLMkEttQEI8D3YK2UaHNvdOff:UHsRMkAtpYIcvcff
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright
Assembly Version: 1.0.0.0
InternalName: 34.exe
FileVersion: 0.0.0.0
CompanyName: Company
LegalTrademarks: Trademark
Comments: Encode & Decode Files
ProductName: Product
ProductVersion: 0.0.0.0
FileDescription: Zero0x@DecodeFile
OriginalFilename: 34.exe

Razy.649460 also known as:

BkavW32.LarticaLTR.Trojan
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.649460
FireEyeGeneric.mg.1a9c824468115991
ALYacGen:Variant.Razy.649460
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0055e39a1 )
BitDefenderGen:Variant.Razy.649460
K7GWTrojan ( 0055e39a1 )
Cybereasonmalicious.468115
BitDefenderThetaGen:NN.ZemsilF.34804.Wm0@ayPFznpG
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Backdoor.Win32.Generic
NANO-AntivirusTrojan.Win32.Resetter.dkkfyp
TencentWin32.Trojan.Generic.Eaee
Ad-AwareGen:Variant.Razy.649460
SophosML/PE-A + Troj/MSILInj-HI
ComodoMalware@#kbmlfko0qisx
F-SecureTrojan.TR/Inject.xbbeicg
DrWebTrojan.PWS.Stealer.13061
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
EmsisoftGen:Variant.Razy.649460 (B)
IkarusTrojan.MSIL.Injector
AviraTR/Inject.xbbeicg
Antiy-AVLTrojan[Backdoor]/Win32.DarkKomet
KingsoftWin32.Hack.DarkKomet.dt.(kcloud)
MicrosoftBackdoor:Win32/Fynloski.A
ArcabitTrojan.Razy.D9E8F4
ZoneAlarmHEUR:Backdoor.Win32.Generic
GDataGen:Variant.Razy.649460
CynetMalicious (score: 90)
AhnLab-V3Win-Trojan/MDA.19171308.X1376
McAfeeGenericRXAA-XX!1A9C82446811
MAXmalware (ai score=86)
VBA32CIL.StupidPInvoker-2.Heur
PandaTrj/CI.A
ESET-NOD32a variant of MSIL/Injector.ERC
RisingBackdoor.Fynloski!8.1FD (CLOUD)
YandexTrojan.Injector!49kvCl+PTyI
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetMSIL/Injector.ELR!tr
AVGMSIL:GenMalicious-EJH [Trj]
AvastMSIL:GenMalicious-EJH [Trj]
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Win32/Backdoor.6f7

How to remove Razy.649460?

Razy.649460 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment