Malware

How to remove “Razy.715479”?

Malware Removal

The Razy.715479 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.715479 virus can do?

  • Creates RWX memory
  • Reads data out of its own binary image
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • A process was set to shut the system down when terminated
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

jhk254jhser.duckdns.org

How to determine Razy.715479?


File Info:

crc32: 6CA83C92
md5: b8fa1571729761d84d9aecb3137589a2
name: B8FA1571729761D84D9AECB3137589A2.mlw
sha1: af93351b823881159af6f5e962e60b523c67535b
sha256: dcc155f184011e6be7d5ec4ce27854852c4cd89c6cefdf1aa3e79de4931a1d3c
sha512: 65bc7048fa674b3cabd78171e3e056c4c5b7bb1ead08d75c0c27098d2f706e7979da31fbaa1fe4056f48d4e0c00099af37001f5f85f18a6232685bd3a0ecb9fe
ssdeep: 1536:oQvY/tXezMCUny6pZ06Ab4ZfughH4T9YUp:Tw/tUMCUHpu6o4ZLhY1p
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2017
Assembly Version: 1.0.0.0
InternalName: Service.exe
FileVersion: 1.0.0.0
ProductName: Service
ProductVersion: 1.0.0.0
FileDescription: Service
OriginalFilename: Service.exe

Razy.715479 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.DownLoader19.37002
MicroWorld-eScanGen:Variant.Razy.715479
FireEyeGeneric.mg.b8fa1571729761d8
McAfeeArtemis!B8FA15717297
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.MSIL.Bladabindi.m!c
SangforMalware
K7AntiVirusTrojan ( 004f6bb11 )
BitDefenderGen:Variant.Razy.715479
K7GWTrojan ( 004f6bb11 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZemsilF.34804.eq3@aK!eC0d
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.MSIL.Generic
NANO-AntivirusTrojan.Win32.Bladabindi.esljrm
RisingBackdoor.Bladabindi!8.B1F (TFE:C:EsTOkkqELzU)
Ad-AwareGen:Variant.Razy.715479
EmsisoftGen:Variant.Razy.715479 (B)
ComodoMalware@#1yrep2bxdt4do
F-SecureTrojan.TR/ATRAPS.Gen
McAfee-GW-EditionBehavesLike.Win32.Generic.kh
SophosMal/Generic-S
IkarusTrojan-Downloader.MSIL.Small
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan/MSIL.Disfa
MicrosoftBackdoor:MSIL/Bladabindi!rfn
ArcabitTrojan.Razy.DAEAD7
ZoneAlarmHEUR:Trojan.MSIL.Generic
GDataGen:Variant.Razy.715479
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/MSILKrypt09.Exp
VBA32Trojan.MSIL.Disfa
ALYacGen:Variant.Razy.715479
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Kryptik.ICO
TencentMalware.Win32.Gencirc.11496d85
YandexTrojan.Disfa!INhpU19puJQ
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetMSIL/Kryptik.ICO!tr
AVGWin32:Malware-gen
Cybereasonmalicious.172976
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.2ec

How to remove Razy.715479?

Razy.715479 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment