Malware

Razy.682550 (file analysis)

Malware Removal

The Razy.682550 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.682550 virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Razy.682550?


File Info:

crc32: 694F91FC
md5: 9211742e071cabee67bb81a14a9d3802
name: sendhookfile.exe
sha1: 709bc297fd74849f437f20763d0a4ab702aa04d4
sha256: a26d034470b8d4e42712deee35d231d50a38096c3dca765038439d5b7674ca88
sha512: 346b1c413b1d0ff783b19c76ea9a9da6c7f192687fd4e28f8c652c52db1111fccfcf090c81f9c1707a80238c55b63b73fe4d70be90077f67162e7246184f32bb
ssdeep: 96:VmUKVFt6nZNIwnZN42gensM9TW6Xhl2N5AuFa9woKDmn1bEcW0qWHPi6pUDZaRC:dIw427f5hlW5BFa9wi20qWHPiDuCxR
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2020
Assembly Version: 1.0.0.0
InternalName: sendhookfile.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: sendhookfile
ProductVersion: 1.0.0.0
FileDescription: sendhookfile
OriginalFilename: sendhookfile.exe

Razy.682550 also known as:

MicroWorld-eScanGen:Variant.Razy.682550
FireEyeGeneric.mg.9211742e071cabee
McAfeeArtemis!9211742E071C
VIPRETrojan.Win32.Generic!BT
K7AntiVirusPassword-Stealer ( 0056a7ae1 )
BitDefenderGen:Variant.Razy.682550
K7GWPassword-Stealer ( 0056a7ae1 )
Cybereasonmalicious.7fd748
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
GDataGen:Variant.Razy.682550
AlibabaTrojan:MSIL/Discord.5f6addde
AegisLabTrojan.Win32.Razy.4!c
RisingStealer.Discord!8.10A86 (CLOUD)
SophosMal/Generic-S
F-SecureTrojan.TR/PSW.Discord.tbkud
DrWebTrojan.PWS.StealerNET.70
EmsisoftGen:Variant.Razy.682550 (B)
IkarusTrojan.MSIL.PSW
CyrenW32/Trojan.NLOF-8063
AviraTR/PSW.Discord.tbkud
MAXmalware (ai score=88)
ArcabitTrojan.Razy.DA6A36
MicrosoftTrojan:Win32/Ymacco.AA88
AhnLab-V3Malware/Win32.RL_Generic.C4143349
ALYacGen:Variant.Razy.682550
Ad-AwareGen:Variant.Razy.682550
MalwarebytesSpyware.PasswordStealer
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/PSW.Discord.HZ
TrendMicro-HouseCallTROJ_GEN.R002H0CGH20
FortinetMSIL/Discord.HZ!tr.pws
BitDefenderThetaGen:NN.ZemsilCO.34136.am0@aKVtTUk
AVGWin32:MalwareX-gen [Trj]
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Generic/Trojan.PSW.5ac

How to remove Razy.682550?

Razy.682550 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment