Malware

Should I remove “Razy.6504”?

Malware Removal

The Razy.6504 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.6504 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Detects Sandboxie through the presence of a library
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
xjpakmdcfuqe.in
xjpakmdcfuqe.ru
xjpakmdcfuqe.com
xjpakmdcfuqe.biz
xjpakmdcfuqe.nl

How to determine Razy.6504?


File Info:

crc32: B6ADAC36
md5: c9d6d556c0458d16ae9f920865b85f30
name: C9D6D556C0458D16AE9F920865B85F30.mlw
sha1: 822a3e4ac2d5648e82279bc6313b5c18a012dab6
sha256: 88ca4b0272708e58db3f3ae35d8cdf08116a843cf1fdb4bca79bf04f9a946dcb
sha512: 22520b9b4b8468244cdd4a43f120570e0620358e7abd6cb2cf8eb72b160a7f683328c95ff3b50155b90ee0fa9607a3558b1b2f0d0fa28eaf11253f42d08ad144
ssdeep: 1536:u9Qz4tTGbYCVGSSPJ2qZwmFukLZISPSg6uneNfxOreRQ:u9U4tqbcfBGmT94g6WeNfxOB
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: charmap.exe
FileVersion: 5.2.3668.0
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 5.2.3668.0
FileDescription: Character Map
OriginalFilename: charmap.exe
Translation: 0x0409 0x04b0

Razy.6504 also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.6504
FireEyeGeneric.mg.c9d6d556c0458d16
CAT-QuickHealWorm.Gamarue.B
Qihoo-360HEUR/QVM20.1.44A7.Malware.Gen
McAfeePWS-Zbot-FANF!C9D6D556C045
CylanceUnsafe
VIPRETrojan.Win32.Reveton.a (v)
SangforMalware
K7AntiVirusEmailWorm ( 003247681 )
BitDefenderGen:Variant.Razy.6504
K7GWEmailWorm ( 003247681 )
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/Zbot.IA.gen!Eldorado
SymantecPacked.Generic.403
APEXMalicious
ClamAVWin.Malware.Razy-6795826-0
KasperskyHEUR:Trojan.Win32.Generic
Ad-AwareGen:Variant.Razy.6504
TACHYONTrojan/W32.PornoAsset.65024.E
SophosMal/ZboCheMan-D
F-SecureBackdoor.BDS/Androm.EB.73
InvinceaML/PE-A + Mal/ZboCheMan-D
McAfee-GW-EditionPWS-Zbot-FANF!C9D6D556C045
EmsisoftGen:Variant.Razy.6504 (B)
JiangminTrojan/PornoAsset.oif
WebrootW32.Worm.Iommna
AviraBDS/Androm.EB.73
MicrosoftWorm:Win32/Gamarue.I
GridinsoftTrojan.Heur!.020520A1
ArcabitTrojan.Razy.D1968
SUPERAntiSpywareTrojan.Agent/Gen-Zbot
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Razy.6504
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win32.Zbot.R49851
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34634.d00@aui03Vni
ALYacGen:Variant.Razy.6504
MAXmalware (ai score=89)
VBA32SScope.Backdoor.IRCBot.3013
MalwarebytesTrojan.Agent
ESET-NOD32a variant of Win32/Kryptik.ASMW
YandexTrojan.GenAsa!qjlH8F5JOJo
SentinelOneStatic AI – Malicious PE
FortinetW32/Zbot.ANQ!tr
AVGWin32:Fareit-CW [Trj]
PandaTrj/Genetic.gen

How to remove Razy.6504?

Razy.6504 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment