Malware

Razy.664486 removal

Malware Removal

The Razy.664486 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.664486 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

redme.redirectme.net

How to determine Razy.664486?


File Info:

crc32: 98F2379A
md5: b92e4d0f653a7c45d6b792bfeb77a19d
name: B92E4D0F653A7C45D6B792BFEB77A19D.mlw
sha1: 1173141874d743b2122d80762c65c69183862155
sha256: 4f91ed71d817f12cfd9849ed17e4969d0034ed78279745bc5d52112b77626d54
sha512: 04c6a0e0ea8bb7581d9e2244d5e32e10f9d0ca105d08460242c8373b5733507b5282e9c946241b300e71931fc8ec798c41e2b7e2eca192c2ea4a5f8bcb47c2a8
ssdeep: 3072:hx9avxaJVYYPwtl7S4wNOL0UVatey0AH+j1MwNQ57P7y/FWJT53FjxTRsp:v9wxowtxS4AkY+j1Mvy/45Vd6p
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2014
Assembly Version: 1.0.0.0
InternalName: 6736362.exe
FileVersion: 1.0.0.0
CompanyName: Microsoft Corporation
Comments: Microsoft
ProductName: 6736362
ProductVersion: 1.0.0.0
FileDescription: Microsoft
OriginalFilename: 6736362.exe

Razy.664486 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.664486
FireEyeGeneric.mg.b92e4d0f653a7c45
McAfeeArtemis!B92E4D0F653A
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
BitDefenderGen:Variant.Razy.664486
K7GWTrojan ( 700000121 )
Cybereasonmalicious.f653a7
BitDefenderThetaGen:NN.ZemsilF.34590.mq3@a4Jag8h
CyrenW32/Trojan.KOGX-0095
SymantecML.Attribute.HighConfidence
TotalDefenseWin32/Tnega.XASH!suspicious
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Blocker.16a0bcd4
NANO-AntivirusTrojan.Win32.Blocker.damprr
TencentWin32.Trojan.Generic.Pepq
Ad-AwareGen:Variant.Razy.664486
TACHYONTrojan/W32.DN-Blocker.200552
SophosMal/Generic-R
ComodoMalware@#1j11brj6louw
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoader9.27678
ZillyaTrojan.Blocker.Win32.24501
TrendMicroTROJ_SPNR.35GA14
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
EmsisoftMalware.Generic.CN1 (A)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.SGeneric
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftBackdoor:Win32/Bladabindi!ml
ArcabitTrojan.Razy.DA23A6
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Razy.664486
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C413877
VBA32Hoax.Blocker
ALYacGen:Variant.Razy.664486
MAXmalware (ai score=100)
PandaTrj/CI.A
ESET-NOD32Win32/Delf.ACW
TrendMicro-HouseCallTROJ_SPNR.35GA14
RisingDropper.Generic!8.35E (CLOUD)
YandexTrojan.Blocker!FPon6n19XE0
IkarusTrojan-Ransom.Blocker
eGambitGeneric.Malware
FortinetW32/Blocker.BA!tr
WebrootW32.Malware.Heur
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.f1d

How to remove Razy.664486?

Razy.664486 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment