Malware

Razy.759482 malicious file

Malware Removal

The Razy.759482 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.759482 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Starts servers listening on 0.0.0.0:443
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Operates on local firewall’s policies and settings
  • Anomalous binary characteristics

How to determine Razy.759482?


File Info:

crc32: 2D1259B7
md5: 4f4f6167abe55072d6b218eb7659b22e
name: 4F4F6167ABE55072D6B218EB7659B22E.mlw
sha1: e5163c4c0c8b62787a85f745057c5b2aded79222
sha256: dfc6dfc52704246597fe43525a276964439da4c93675c10e08ba79a453ff23f0
sha512: 24c633c969f5c54e1f15c67542b307f5097cfb2253e1b57b4a362ded502819080f29f4477a23ae545ba2398270089c7e7db1932e408dea73c7cf94911c91ffae
ssdeep: 12288:hrcppXZ0b0exu8aDuoQ90sHd1ToS9YdfecpC/x5jMlJQbB9WMuuLqa8EmyCg:dwE0cu8aiT9hd1T34WckJuzOf8Emy7
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Razy.759482 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.759482
FireEyeGeneric.mg.4f4f6167abe55072
McAfeeTrojan-FRGC!4F4F6167ABE5
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.Razy.759482
K7GWTrojan ( 005702a91 )
K7AntiVirusTrojan ( 005702a91 )
BitDefenderThetaGen:NN.ZedlaF.34590.ZO4@aSNCawci
CyrenW32/Kryptik.CCI.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:BankerX-gen [Trj]
ClamAVWin.Packed.Generickdz-9772324-0
KasperskyHEUR:Trojan-Banker.Win32.Cridex.vho
NANO-AntivirusTrojan.Win32.Cridex.iaiokg
TencentMalware.Win32.Gencirc.10ce0c6b
Ad-AwareGen:Variant.Razy.759482
F-SecureHeuristic.HEUR/AGEN.1138986
DrWebTrojan.Packed2.42617
InvinceaML/PE-A
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
EmsisoftGen:Variant.Razy.759482 (B)
IkarusTrojan.Win32.Crypt
JiangminTrojan.Banker.Cridex.ald
AviraHEUR/AGEN.1138986
MicrosoftTrojan:Win32/Dridex.MS!MTB
GridinsoftTrojan.Win32.Packed.oa!s2
ArcabitTrojan.Razy.DB96BA
ZoneAlarmHEUR:Trojan-Banker.Win32.Cridex.vho
GDataGen:Variant.Razy.759482
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.MalPe.R352718
VBA32BScope.Trojan.Inject
ALYacGen:Variant.Razy.759482
MAXmalware (ai score=86)
MalwarebytesTrojan.Dridex
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.HGLY
RisingTrojan.Kryptik!8.8 (TFE:1:XaZ8jKDWdXU)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_96%
FortinetW32/Kryptik.HGLY!tr
AVGWin32:BankerX-gen [Trj]
Qihoo-360HEUR/QVM39.1.3967.Malware.Gen

How to remove Razy.759482?

Razy.759482 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment