Categories: Malware

Razy.778646 (file analysis)

The Razy.778646 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.778646 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
www.bing.com
www.xvideos.com
a.tomx.xyz
static-l3.xvideos-cdn.com
www.easyimage.us
easyimage.us

How to determine Razy.778646?


File Info:

crc32: A9287C12md5: 1aec39f2b9fcb993452048d8c6e9ab04name: 1AEC39F2B9FCB993452048D8C6E9AB04.mlwsha1: 3d7f9481fe856134cc7afffa7ca6e25c0b76a0b7sha256: f401057e9f97fb5f05bf7305eec6ed3b2583c0328a229e1e40843e38181c7e2fsha512: 12524b9948b2fbbeb2b25efa8618d7b814bc26e012590515063a11e43ac0c5def53fde82be84aca6bcc3b7ce053e62a9cac9c82e33d25f8edb543bd888512cffssdeep: 6144:/XIlRig+hJzbREsstiKHT641HyWst9XIlRig+hJzbRE:ArD+hJz9EhzuwS8rD+hJz9Etype: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0ProductVersion: 1.00InternalName: filedasFileVersion: 1.00OriginalFilename: filedas.exeProductName: justin

Razy.778646 also known as:

Bkav W32.AIDetect.malware1
Lionic Trojan.Win32.Generic.4!c
DrWeb Trojan.DownLoader6.7805
Cynet Malicious (score: 99)
ALYac Gen:Variant.Razy.778646
Cylance Unsafe
Zillya Downloader.VB.Win32.42332
Sangfor Trojan.Win32.Save.a
Cybereason malicious.2b9fcb
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/TrojanDownloader.VB.PGK
APEX Malicious
Avast Win32:VB-ADJY [Trj]
Kaspersky Trojan-Downloader.Win32.Agent.silqxh
BitDefender Gen:Variant.Razy.778646
NANO-Antivirus Trojan.Win32.Dwn.uxngj
MicroWorld-eScan Gen:Variant.Razy.778646
Tencent Win32.Trojan.Jorik.Ecbk
Ad-Aware Gen:Variant.Razy.778646
Comodo Malware@#1ev1zkkbid3yl
F-Secure Trojan.TR/VB.Downloader.Gen
BitDefenderTheta Gen:NN.ZevbaF.34236.sm0@aGnSbqmi
VIPRE Trojan.Win32.Generic!BT
McAfee-GW-Edition BehavesLike.Win32.Fareit.dc
FireEye Generic.mg.1aec39f2b9fcb993
Emsisoft Gen:Variant.Razy.778646 (B)
SentinelOne Static AI – Malicious PE
Jiangmin Trojan.Jorik.dvt
Avira TR/VB.Downloader.Gen
eGambit Unsafe.AI_Score_100%
Antiy-AVL Trojan/Generic.ASMalwS.35C763
Kingsoft Win32.Heur.KVM006.a.(kcloud)
Microsoft Trojan:Win32/Wacatac.B!ml
SUPERAntiSpyware Heur.Agent/Gen-GalPic
ZoneAlarm Trojan-Downloader.Win32.Agent.silqxh
GData Gen:Variant.Razy.778646
AhnLab-V3 Downloader/Win32.Banker.C161521
VBA32 TrojanDownloader.Agent
MAX malware (ai score=87)
Yandex Trojan.GenAsa!2B1GIXdS4wY
Ikarus Trojan-Downloader.VB
Fortinet W32/VB.PGK!tr.dldr
AVG Win32:VB-ADJY [Trj]
Paloalto generic.ml

How to remove Razy.778646?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

MSIL/Kryptik.ALKW removal tips

The MSIL/Kryptik.ALKW is considered dangerous by lots of security experts. When this infection is active,…

4 mins ago

Generik.SLXLLT (file analysis)

The Generik.SLXLLT is considered dangerous by lots of security experts. When this infection is active,…

8 mins ago

Trojan-Dropper.Win32.Agent.tgljob malicious file

The Trojan-Dropper.Win32.Agent.tgljob is considered dangerous by lots of security experts. When this infection is active,…

39 mins ago

Ransom:MSIL/Hibotibo.AA!MTB information

The Ransom:MSIL/Hibotibo.AA!MTB is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Trojan-Dropper.Win32.Agent.tgbcwu removal guide

The Trojan-Dropper.Win32.Agent.tgbcwu is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Worm.Win32.Vobfus.axhs removal guide

The Worm.Win32.Vobfus.axhs is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago