Malware

Razy.702165 removal

Malware Removal

The Razy.702165 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.702165 virus can do?

  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Attempts to delete volume shadow copies
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Razy.702165?


File Info:

crc32: 13651641
md5: 0ed2ca539a01cdb86c88a9a1604b2005
name: tmp81cps7pz
sha1: 4fed7eae00bfa21938e49f33b7c6794fd7d0750c
sha256: bcdac1a2b67e2b47f8129814dca3bcf7d55404757eb09f1c3103f57da3153ec8
sha512: 34dad101cd7c5f9ff2267674d224986b9274e0e17d9ae665ca1af4ffa57408106238b1e248045465ab17c72a4b92473ab3714aefb705d95f9725a4251379c7e2
ssdeep: 1536:HO88wNYmqdeBk7G7IhhqZKWVKz8NqUxVl2HihgOrT8avvvvvvvvvvvvvvvvvvvv:HOmhqdeBk+nc9OrTZvvvvvvvvvvvvvv
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Razy.702165 also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanGen:Variant.Razy.702165
CAT-QuickHealTrojan.Delshad
ALYacTrojan.Ransom.WastedLocker
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.DelShad.4!c
K7AntiVirusSpyware ( 0054f96e1 )
AlibabaTrojanSpy:Win32/DelShad.a61e9fab
K7GWSpyware ( 0054f96e1 )
Cybereasonmalicious.39a01c
TrendMicroRansom.Win32.WASTEDLOCKER.AA
CyrenW32/Trojan.KQPR-0792
SymantecRansom.WastedLocker
ESET-NOD32a variant of Win32/Filecoder.WastedLocker.A
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.DelShad.dho
BitDefenderGen:Variant.Razy.702165
NANO-AntivirusTrojan.Win32.Encoder.hlhhdt
ViRobotTrojan.Win32.S.Ransom.61440.M
RisingSpyware.Ursnif!8.1DEF (CLOUD)
Ad-AwareGen:Variant.Razy.702165
ComodoMalware@#2p0m0tpi3dfxl
F-SecureTrojan.TR/Crypt.XPACK.Gen3
DrWebTrojan.Encoder.31951
ZillyaTrojan.Ursnif.Win32.11420
Invinceaheuristic
FireEyeGeneric.mg.0ed2ca539a01cdb8
SophosTroj/Agent-BEZX
SentinelOneDFI – Suspicious PE
JiangminTrojan.DelShad.ya
WebrootW32.Ransom.Gen
AviraTR/Crypt.XPACK.Gen3
FortinetW32/DelShad.CR!tr.ransom
Antiy-AVLTrojan/Win32.DelShad
Endgamemalicious (high confidence)
ArcabitTrojan.Razy.DAB6D5
ZoneAlarmTrojan.Win32.DelShad.dho
MicrosoftRansom:Win32/WastedLocker.WT!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4139121
McAfeeRDN/Generic PWS.y
MAXmalware (ai score=100)
VBA32Trojan.DelShad
MalwarebytesRansom.BinADS
TrendMicro-HouseCallRansom.Win32.WASTEDLOCKER.AA
TencentWin32.Trojan.Delshad.Kfy
YandexTrojanSpy.Ursnif!F4l5IsaNKeU
IkarusTrojan-Ransom.WastedLocker
eGambitUnsafe.AI_Score_91%
GDataGen:Variant.Razy.702165
BitDefenderThetaAI:Packer.2F0FB4631E
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.0b1

How to remove Razy.702165?

Razy.702165 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment