Malware

Razy.689028 removal guide

Malware Removal

The Razy.689028 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.689028 virus can do?

  • Executable code extraction
  • Reads data out of its own binary image
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Razy.689028?


File Info:

crc32: 56D7AA8B
md5: a3aaf17f1c6682baaf2f6ec6a08e7f86
name: A3AAF17F1C6682BAAF2F6EC6A08E7F86.mlw
sha1: 9031dc3474f3061a5ad9dfa824b5ea5d2f9a5a57
sha256: 5bea8447cedb34d176f611198045b808519a36c0d2128ad8d4dfe2e2d9e9e381
sha512: 98d9851758aef46c255c1afeb14598240b74628b688da580fbe1bb9b4abfbe4960f8d1d10ba4ebc14b8c5fd2debc3ee5b12e4d1a8bb85627c5e6df8b11874f0e
ssdeep: 768:dUq4jGY5lkxQztcwHny5PKiL0SBe4X4pSp6Xqc9plO6Wa/SlMk0/WTBBHo:dF4C0UwuWy5mqSP7lvHKM7OD
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: Dropbox, Inc
InternalName: xafxb0xbb08
FileVersion: 1.00
CompanyName: Dropbox, Inc
LegalTrademarks: Dropbox, Inc
Comments: Dropbox, Inc
ProductName: Dropbox, Inc
ProductVersion: 1.00
FileDescription: Dropbox, Inc
OriginalFilename: xafxb0xbb08.exe

Razy.689028 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004d68f41 )
Elasticmalicious (high confidence)
CAT-QuickHealTrojan.VBCrypt.MF.4428
ALYacGen:Variant.Razy.689028
MalwarebytesMalware.AI.739048395
CrowdStrikewin/malicious_confidence_60% (D)
K7GWTrojan ( 004d68f41 )
Cybereasonmalicious.f1c668
CyrenW32/VBKrypt.AD.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.BVEX
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 99)
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Razy.689028
NANO-AntivirusTrojan.Win32.BGXC.dpnokc
MicroWorld-eScanGen:Variant.Razy.689028
Ad-AwareGen:Variant.Razy.689028
BitDefenderThetaGen:NN.ZevbaF.34294.dm0@aOEGEybi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Fareit.qm
FireEyeGeneric.mg.a3aaf17f1c6682ba
EmsisoftGen:Variant.Razy.689028 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_98%
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Razy.DA8384
GDataGen:Variant.Razy.689028
AhnLab-V3Trojan/Win32.Injector.C2586392
McAfeeArtemis!A3AAF17F1C66
MAXmalware (ai score=86)
PandaTrj/CI.A
YandexTrojan.Injector!NGO2K4jFSfM
IkarusTrojan.Win32.Injector
FortinetW32/Injector.BWXZ!tr
AVGWin32:Malware-gen

How to remove Razy.689028?

Razy.689028 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment