Malware

Razy.743278 malicious file

Malware Removal

The Razy.743278 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.743278 virus can do?

  • Presents an Authenticode digital signature
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
to-load.ru
a.tomx.xyz

How to determine Razy.743278?


File Info:

crc32: 61D9151B
md5: f163ccea75116b72c13754d07049c9c8
name: F163CCEA75116B72C13754D07049C9C8.mlw
sha1: fe68d7bb100f9d8ace0af44e5924e6cf9e8ab176
sha256: 2feff422eed5c3552e18f313c454bf49e549dcbba7dbe89c9f3aa7fc9a989ebc
sha512: 7b687c32b5c94ef98571cc3c622c1cd636039231ddcd4746e860e18ea064e1b0e4f9809778bb26a17e38da405d9da8012282caff37e06e662e8a2faf957eb7e9
ssdeep: 768:U2DUwYfXOhLW0WkWMtmBVuLZKVW6Dhfi2l/vHlNwcQgUUpcXUFs641IKWD2MU0l:a/vsW0WkWHVwZMi2l/ygHgUNrrpH
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright c 2005 - 2012
InternalName: Downloader
FileVersion: 1, 0, 0, 0
ProductName: Downloader
ProductVersion: 1, 0, 0, 0
FileDescription: Downloader
OriginalFilename: Downloader.exe
Translation: 0x0419 0x04e3

Razy.743278 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.743278
FireEyeGeneric.mg.f163ccea75116b72
CAT-QuickHealTrojan.Downloader.Agent.VF5
McAfeePUP-FFK
MalwarebytesPUP.Optional.DownWare.RU
ZillyaDownloader.Agent.Win32.155964
SangforMalware
K7AntiVirusDialer ( 0040f5991 )
BitDefenderGen:Variant.Razy.743278
K7GWAdware ( 004ed1fd1 )
Cybereasonmalicious.a75116
BaiduWin32.Adware.Generic.ar
CyrenW32/Agent.RC.gen!Eldorado
SymantecSMG.Heur!gen
TotalDefenseWin32/Tnega.ARLO
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Downloader-3957
AlibabaDownloader:Win32/LoadMoney.90e86ac2
NANO-AntivirusTrojan.Win32.LMN.crokry
ViRobotAdware.Razy.61376.AO
TencentAdware.Win32.DL.Lmn.b
Ad-AwareGen:Variant.Razy.743278
EmsisoftGen:Variant.Razy.743278 (B)
ComodoApplicUnwnt.Win32.LoadMoney.B@4th5ev
F-SecureProgram.APPL/LoadMoney.7009
DrWebAdware.Downware.774
VIPRETrojan.Win32.Dwnldr.y (v)
TrendMicroTROJ_GEN.R002C0OLU20
McAfee-GW-EditionPUP-FFK
SophosMal/Dwnldr-Y
IkarusTrojan.SuspectCRC
JiangminTrojan/Genome.cqut
eGambitUnsafe.AI_Score_98%
AviraAPPL/LoadMoney.7009
Antiy-AVLTrojan/Win32.SGeneric
KingsoftWin32.HeurC.KVM019.a.(kcloud)
ArcabitTrojan.Razy.DB576E
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
ZoneAlarmnot-a-virus:Downloader.Win32.LMN.e
GDataWin32.Riskware.StartPage.J
CynetMalicious (score: 100)
AhnLab-V3Adware/Win32.Downloader.R47466
Acronissuspicious
ALYacGen:Variant.Razy.743278
MAXmalware (ai score=99)
VBA32Downware.LMN.gen
ESET-NOD32a variant of Win32/LoadMoney.A potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002C0OLU20
RisingTrojan.DL.Small!1.65D6 (CLASSIC)
YandexTrojan.GenAsa!6V58Fn+urBk
SentinelOneStatic AI – Suspicious PE – Adware
MaxSecurenot-a-virus:.Downloader.Agent.vf
FortinetW32/Agent.FEZ!tr.dldr
Webroot
CrowdStrikewin/malicious_confidence_60% (D)
Qihoo-360Win32/Sorter.AutoVirus.70Binder.A

How to remove Razy.743278?

Razy.743278 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment