Malware

Should I remove “Razy.738158”?

Malware Removal

The Razy.738158 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.738158 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • Sniffs keystrokes
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Attempts to create or modify system certificates
  • Makes SMTP requests, possibly sending spam or exfiltrating data.

Related domains:

z.whorecord.xyz
a.tomx.xyz
smtp.gmail.com

How to determine Razy.738158?


File Info:

crc32: 89C67CB8
md5: b142181589f2664efd8facab594d4010
name: B142181589F2664EFD8FACAB594D4010.mlw
sha1: 9a81b0660f280361a5124cbae7771814b41200b0
sha256: 380bb929c31502121b26dc652b716ad498ef5dfe5feaf043a0828048cd845e59
sha512: c3b46d8668503ef0dc8d0f66fff22569301522dcdf2dfd69a6d6ff0da1d1fe2bcad6f4d0c4e60e050700205a0d68b8d5d36d56d05069438bd9e361e3aa7c0f84
ssdeep: 768:FgPL9XpxFMWSfY3ojYWo8YgMADW3lw4MTOlSFC7LZ:FgPwY3dWPuSb4nouZ
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Telegfars 2018
Assembly Version: 1.0.0.1
InternalName: milad.exe
FileVersion: 0.0.0.2
CompanyName: Telegfars 2018
Comments: Telegram Add Memmber
ProductName: 2018
ProductVersion: 0.0.0.2
FileDescription: Telegram Add Memmber
OriginalFilename: milad.exe

Razy.738158 also known as:

LionicTrojan.Win32.Generic.4!c
DrWebTrojan.MulDrop8.15471
McAfeeArtemis!B142181589F2
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
K7GWSpyware ( 003624591 )
K7AntiVirusSpyware ( 003624591 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Spy.Keylogger.AJV
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 99)
KasperskyTrojan-Ransom.Win32.Blocker.kyqi
BitDefenderGen:Variant.Razy.738158
NANO-AntivirusTrojan.Win32.Blocker.faolho
MicroWorld-eScanGen:Variant.Razy.738158
TencentWin32.Trojan.Blocker.Pcic
Ad-AwareGen:Variant.Razy.738158
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34058.cm0@aG4eC@c
VIPRETrojan.Win32.Generic!BT
FireEyeGeneric.mg.b142181589f2664e
EmsisoftGen:Variant.Razy.738158 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Blocker.qwb
AviraTR/Spy.Gen
MicrosoftBackdoor:Win32/Bladabindi!ml
ArcabitTrojan.Razy.DB436E
ZoneAlarmTrojan-Ransom.Win32.Blocker.kyqi
GDataGen:Variant.Razy.738158
MAXmalware (ai score=99)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
YandexTrojan.Blocker!FPRmEAFMfuo
IkarusTrojan.Msil
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.BO!tr.spy
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HgIASVUA

How to remove Razy.738158?

Razy.738158 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment