Malware

Razy.656052 removal guide

Malware Removal

The Razy.656052 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.656052 virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Detects Sandboxie through the presence of a library
  • Checks for the presence of known windows from debuggers and forensic tools
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Network activity detected but not expressed in API logs
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz

How to determine Razy.656052?


File Info:

crc32: 486D4905
md5: 995614e79d5769647cb909d0385cc499
name: adobeplayer21.exe
sha1: 6878572eaa1f7a27b7aa9d5782a2f1b9d6a06270
sha256: 9d9b25f13056b78010c2ee77c0141c7a22c2852f89653d7ec3a9afa0fa93ed54
sha512: f27bb1a5277e02d37e7a9c9d4eb598637a186e35e76f218964d342eb2800fe7944cfd30851ae9fcc5250c612436d4c0ddb7c220edcdacc585079b04dc35554d0
ssdeep: 49152:EaZwoEQgj1q8D3YGVOdBTgtw8DovVEnVVcWiPdf9w+Njb4qW/nVLY96LUO/4kvM:tKQGqQVObT0w8DZnI9wX5+bR+M
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Razy.656052 also known as:

BkavW32.HfsAutoB.
MicroWorld-eScanGen:Variant.Razy.656052
FireEyeGeneric.mg.995614e79d576964
ALYacGen:Variant.Razy.656052
BitDefenderGen:Variant.Razy.656052
Cybereasonmalicious.79d576
BitDefenderThetaGen:NN.ZexaE.34108.2AY@aejNnMci
AvastWin32:Malware-gen
GDataGen:Variant.Razy.656052
KasperskyTrojan.Win32.Vasal.atm
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
Ad-AwareGen:Variant.Razy.656052
F-SecureTrojan.TR/Dropper.Gen
ZillyaTrojan.Vasal.Win32.123
Invinceaheuristic
McAfee-GW-EditionArtemis
EmsisoftGen:Variant.Razy.656052 (B)
AviraTR/Dropper.Gen
Endgamemalicious (high confidence)
ArcabitTrojan.Razy.DA02B4
ZoneAlarmTrojan.Win32.Vasal.atm
MicrosoftTrojan:Win32/Wacatac.C!ml
Acronissuspicious
McAfeeArtemis!995614E79D57
MAXmalware (ai score=82)
VBA32Trojan.MSIL.gen.11
ESET-NOD32a variant of Win32/Packed.Themida.HLJ
RisingMalware.Heuristic!ET#95% (RDMK:cmRtazp/NEAGDKyoAZXABfZpAYbl)
SentinelOneDFI – Malicious PE
eGambitPE.Heur.InvalidSig
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_80% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove Razy.656052?

Razy.656052 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment