Malware

What is “Razy.776028 (B)”?

Malware Removal

The Razy.776028 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.776028 (B) virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Razy.776028 (B)?


File Info:

crc32: 47505D73
md5: 72e221f6f943e44e89a7d1c697f7b6c8
name: 72E221F6F943E44E89A7D1C697F7B6C8.mlw
sha1: 5fc8520a76f5e9174fdb2665f4fda7b12324482f
sha256: 56ad6d57b4f63b71b9a594ead5b8b74dcc9669b914395e3801d49610bf3a10b3
sha512: 464968a1e413b5f04344f8af9bbac25b7ac6dbd35ba110dfb055ecef666bece742ed62c996a071383fb7f4a3d6e4c987437c49cecd989795b2df0c83434e1d2e
ssdeep: 6144:JKMxrqxH6cd1b3QGLwUuxOd4RFxXGjjMvVCj/Go5NRAE:qHrdpjq4GFxXGHMvVCrdfRz
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 Headlight Software, Inc. All rights reserved.
InternalName: AdminPrivSetting.exe
FileVersion: 1.0.6.5
CompanyName: Headlight Software, Inc.
ProductName: (Shared by Headlight Software Products)
ProductVersion: 1.0.6.5
FileDescription: Change Settings that need Admin Privileges
OriginalFilename: AdminPrivSetting.exe
Translation: 0x0409 0x04e4

Razy.776028 (B) also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.776028
FireEyeGeneric.mg.72e221f6f943e44e
ALYacGen:Variant.Razy.776028
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.Razy.776028
K7GWTrojan ( 005721d11 )
K7AntiVirusTrojan ( 005721d11 )
BitDefenderThetaGen:NN.ZexaF.34590.tq1@aCyEbPpi
CyrenW32/Agent.BYW.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:BankerX-gen [Trj]
ClamAVWin.Packed.Mint-9784350-0
KasperskyHEUR:Trojan-Banker.Win32.Qbot.vho
NANO-AntivirusVirus.Win32.Gen.ccmw
TencentMalware.Win32.Gencirc.10ce0f5f
Ad-AwareGen:Variant.Razy.776028
SophosTroj/Agent-AJFK
DrWebTrojan.Inject4.4287
InvinceaML/PE-A + Troj/Agent-AJFK
McAfee-GW-EditionGenericRXMN-MU!72E221F6F943
EmsisoftGen:Variant.Razy.776028 (B)
IkarusTrojan.Win32.Gencbl
JiangminTrojan.Zenpak.dsu
MAXmalware (ai score=88)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Qakbot.AR!Cert
GridinsoftTrojan.Win32.Packed.oa!s2
ArcabitTrojan.Razy.DBD75C
SUPERAntiSpywareTrojan.Agent/Generic
AhnLab-V3Trojan/Win32.Qakbot.R354673
ZoneAlarmHEUR:Trojan-Banker.Win32.Qbot.vho
GDataGen:Variant.Razy.776028
CynetMalicious (score: 100)
ESET-NOD32a variant of Win32/Kryptik.HHDH
Acronissuspicious
McAfeeGenericRXMN-MU!72E221F6F943
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Qbot
RisingTrojan.Kryptik!1.CE73 (CLASSIC)
SentinelOneStatic AI – Malicious PE
eGambitPE.Heur.InvalidSig
FortinetW32/Kryptik.HGKG!tr
AVGWin32:BankerX-gen [Trj]
Cybereasonmalicious.a76f5e
MaxSecureTrojan.Malware.121218.susgen

How to remove Razy.776028 (B)?

Razy.776028 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment