Malware

About “Razy.711909” infection

Malware Removal

The Razy.711909 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.711909 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Attempts to restart the guest VM
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz
edgedl.me.gvt1.com
update.googleapis.com

How to determine Razy.711909?


File Info:

crc32: 052D2876
md5: 3b8beb368d0ad4672585837851a82ee9
name: 3B8BEB368D0AD4672585837851A82EE9.mlw
sha1: be8c99f978fc539c8c76fe3716ae0aff8b4010b7
sha256: cd4799c732320552991e0c658309ee6e6dce3952a830444b70e6a60c12485280
sha512: 8e4da1efbc34e59a153c15f4955278190340d7f73228d6fd69d47ad3425648f66de45e57a7cf17902877278093cfa61c1fa812192789d0e4015951882ca0a67f
ssdeep: 1536:o9HUnJAzSaaLHwUEgj/zTP8nqIC67xlJL4SpDnN3Za0DirLmqLYNsayC9x:opUnJAz7aLHw7grUnqrkxgSpLB2FL0y
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2008 g10 Code GmbH
FileVersion: 2.1.0.1608
CompanyName: g10 Code GmbH
LegalTrademarks:
Comments: GPG4Win is Free Software; you can redistribute it and/or modify it under the terms of the GNU General Public License. You should have received a copy of the GNU General Public License along with this software; if not, write to the Free Software Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA
ProductName: GPG4Win (2.1.0-rc1)
FileDescription: Gpg4win: The GNU Privacy Guard and Tools for Windows

Razy.711909 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055dd191 )
DrWebTrojan.MulDrop.65387
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.711909
CylanceUnsafe
ZillyaTrojan.Yakes.Win32.2898
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Obfuscator.3b892b47
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.68d0ad
CyrenW32/Ransom.S.gen!Eldorado
SymantecTrojan.Ransomlock!gen1
ESET-NOD32a variant of Win32/Kryptik.LRV
APEXMalicious
AvastWin32:Susn-BC [Trj]
ClamAVWin.Dropper.Zeus-9828870-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.711909
NANO-AntivirusTrojan.Win32.Yakes.jcecs
MicroWorld-eScanGen:Variant.Razy.711909
TencentWin32.Trojan.Yakes.woh
Ad-AwareGen:Variant.Razy.711909
SophosML/PE-A + Mal/FakeAV-MR
ComodoMalware@#3dyksm6jbqfih
BitDefenderThetaGen:NN.ZexaF.34110.hmKfaC71prFk
VIPRETrojan.Win32.FakeAV.gq (v)
McAfee-GW-EditionBehavesLike.Win32.Trojan.cc
FireEyeGeneric.mg.3b8beb368d0ad467
EmsisoftGen:Variant.Razy.711909 (B)
JiangminTrojan/Yakes.cdn
AviraTR/Crypt.XPACK.Gen
eGambitGeneric.Downloader
Antiy-AVLTrojan/Generic.ASMalwS.1859C11
KingsoftWin32.Troj.Yakes.n.(kcloud)
MicrosoftRansom:Win32/LockScreen.BR
GDataGen:Variant.Razy.711909
AhnLab-V3Trojan/Win32.Ransomlock.R7390
McAfeeGenericRXKW-RI!3B8BEB368D0A
MAXmalware (ai score=100)
VBA32Trojan.ExpProc.014
MalwarebytesMalware.AI.3599739892
PandaGeneric Malware
IkarusTrojan-Ransom.HmBlocker
MaxSecureTrojan.Malware.3631471.susgen
FortinetW32/BrowHost.KP!tr
AVGWin32:Susn-BC [Trj]
Paloaltogeneric.ml

How to remove Razy.711909?

Razy.711909 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment