Malware

What is “Razy.675809”?

Malware Removal

The Razy.675809 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.675809 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

edgedl.me.gvt1.com
update.googleapis.com

How to determine Razy.675809?


File Info:

crc32: 8EDA9E76
md5: 6a1770800c9c2e44222e93ddacb8bbcf
name: 6A1770800C9C2E44222E93DDACB8BBCF.mlw
sha1: baac8fd5fc67463d990218c38734ee19e173156f
sha256: 5765c3b7b0312d0cd76e83c27e492f2eb5f2d079a9adb2bb016b0443adec0216
sha512: cb09a920306135a7a25ef3a6ee542c5320d07cdfdb244498744952ed7adc1c753ba11847cd0d253f4be49e30bd63456204e8c5a0b672dc0bbc2c82a964271890
ssdeep: 384:GDEFH/A+JMbwVnXxxBHKLiXy7JegH8KU9YBXFH3L9:Vo+JMbO4LijgH8r9YXH5
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 2.5.0.0
InternalName: Test 1.exe
FileVersion: 2.5.0.0
Comments: Use at your own risk - For education purposes only
ProductVersion: 2.5.0.0
FileDescription: TF2 Item Generator
OriginalFilename: Test 1.exe

Razy.675809 also known as:

K7AntiVirusTrojan ( 700000121 )
Elasticmalicious (high confidence)
ALYacGen:Variant.Razy.675809
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7GWTrojan ( 700000121 )
Cybereasonmalicious.00c9c2
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/LockScreen.FJ
APEXMalicious
AvastMSIL:Downloader-KH [Trj]
KasperskyTrojan-Ransom.Win32.Blocker.bjpr
BitDefenderGen:Variant.Razy.675809
NANO-AntivirusTrojan.Win32.Blocker.fbdrdo
MicroWorld-eScanGen:Variant.Razy.675809
TencentWin32.Trojan.Blocker.boep
Ad-AwareGen:Variant.Razy.675809
SophosMal/Generic-R + Troj/RansMSIL-A
ComodoMalware@#1r2x43u9vucrp
BitDefenderThetaGen:NN.ZemsilF.34790.cm0@a0kDwXb
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionTrojan-FCYR!6A1770800C9C
FireEyeGen:Variant.Razy.675809
EmsisoftGen:Variant.Razy.675809 (B)
SentinelOneStatic AI – Malicious PE
WebrootPua.Gen
AviraHEUR/AGEN.1115178
Antiy-AVLTrojan/Generic.ASMalwS.268705
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftRansom:MSIL/Genasom.G
GDataGen:Variant.Razy.675809
McAfeeTrojan-FCYR!6A1770800C9C
MAXmalware (ai score=83)
VBA32Hoax.Blocker
PandaGeneric Malware
YandexTrojan.Blocker!I8IOG5o7KHM
IkarusTrojan-Ransom.Blocker
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/LockScreen.FU!tr
AVGMSIL:Downloader-KH [Trj]
Qihoo-360Win32/Ransom.Genasom.HgIASSwA

How to remove Razy.675809?

Razy.675809 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment