Malware

Razy.693659 malicious file

Malware Removal

The Razy.693659 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.693659 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Checks for the presence of known windows from debuggers and forensic tools
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

rapontoperito.pw

How to determine Razy.693659?


File Info:

crc32: DEEAB10A
md5: 790ca2c09f5f1868b61f31451f377f3b
name: bj2.exe
sha1: be67455cde32895d5bbca5a57c4c9de5efe462ed
sha256: dd96397e468dd62f5f56b24a0a02b757df5f11fbc86f19242c105b654fe4c802
sha512: 3d402c512e7161122f48230dc1e979d1e743a589d882dfd3c8da5be084089edae55c355a2989958f72d121d7c515ed493909432ddb00eca6968e75de0111ef78
ssdeep: 49152:Nf6rFlskmgCnAt1wLjT5V1o+iHyaCOTFC6J7iTddwtY9TjV9EC59fx7GGFrnFQNQ:qFlsk/ajyiTddwtqnV6C59fxdMc5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2018 - 2020
Assembly Version: 1.0.4.0
InternalName: UjnmnmZzkrLGxXg.exe
FileVersion: 1.0.4.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: Chess Console
ProductVersion: 1.0.4.0
FileDescription: Chess Console
OriginalFilename: UjnmnmZzkrLGxXg.exe

Razy.693659 also known as:

BkavW32.AIDetectVM.malwareA
MicroWorld-eScanGen:Variant.Razy.693659
FireEyeGeneric.mg.790ca2c09f5f1868
Qihoo-360Generic/Trojan.61f
McAfeeArtemis!790CA2C09F5F
CylanceUnsafe
AegisLabTrojan.Win32.Midie.4!c
K7AntiVirusTrojan ( 0056438c1 )
BitDefenderGen:Variant.Razy.693659
K7GWTrojan ( 0056438c1 )
Cybereasonmalicious.cde328
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
GDataGen:Variant.Razy.693659
KasperskyTrojan.Win32.Chapak.enek
AlibabaPacked:Win32/Themida.cf2827b3
NANO-AntivirusVirus.Win32.Gen.ccmw
RisingMalware.Heuristic!ET#98% (RDMK:cmRtazp6bEOftxAQ6VqzWDJ+cnOL)
Endgamemalicious (high confidence)
SophosMal/Generic-S
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.BadFile.rc
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Razy.693659 (B)
IkarusTrojan.Win32.Themida
MAXmalware (ai score=84)
ArcabitTrojan.Razy.DA959B
ZoneAlarmTrojan.Win32.Chapak.enek
MicrosoftTrojan:Win32/Wacatac.C!ml
VBA32BScope.Trojan.Megumin
ALYacGen:Variant.Midie.71557
Ad-AwareGen:Variant.Razy.693659
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Packed.Themida.HKO
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_93%
FortinetW32/PossibleThreat
BitDefenderThetaGen:NN.ZexaF.34128.@V0@auBNT!pi
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (W)

How to remove Razy.693659?

Razy.693659 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment