Malware

Razy.784829 (file analysis)

Malware Removal

The Razy.784829 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.784829 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • A scripting utility was executed
  • Attempts to remove evidence of file being downloaded from the Internet
  • Code injection with CreateRemoteThread in a remote process
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
google.de
sams1234.ddns.net

How to determine Razy.784829?


File Info:

crc32: 6AEFF424
md5: 8da04785c40e487c3ad11281773f6cd6
name: 8DA04785C40E487C3AD11281773F6CD6.mlw
sha1: b02f803a33adc8855e2bc6c10055ba6a0cd25720
sha256: 80c1d555427524bfe8b945673be38691c9dd2bf32b39e3515871e0f8cd833a9d
sha512: 8855a139297c99640a2f822edb22abe0f05dfbe45a3d25864b19a5fbac9d157e0d70fbab874803af00f36f6fc4f7287d5ba4c91c970c88b84c7e781be89d9e7e
ssdeep: 12288:ibN8JhxmMmESSf3+ZRB+EpsDy+7Cg3yTB1t6gMvlTpa6NYjHhtkafwyg:o8J3/OYEpsDnCA+1Ea1jBHfwy
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Razy.784829 also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanGen:Variant.Razy.784829
McAfeeGenericRXAA-AA!8DA04785C40E
CylanceUnsafe
SangforMalware
BitDefenderGen:Variant.Razy.784829
K7GWTrojan ( 00572bf21 )
ArcabitTrojan.Razy.DBF9BD
CyrenW32/Agent.BZP.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:RATX-gen [Trj]
KasperskyTrojan.Win32.Zonidel.fgk
AlibabaTrojan:Win32/Kryptik.21101929
ViRobotTrojan.Win32.Z.Razy.998400.AI
Ad-AwareGen:Variant.Razy.784829
EmsisoftGen:Variant.Razy.784829 (B)
F-SecureTrojan.TR/Crypt.Agent.sbjaw
DrWebTrojan.PWS.Siggen2.58711
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
FireEyeGeneric.mg.8da04785c40e487c
IkarusTrojan.Win32.Crypt
JiangminTrojanSpy.AveMaria.lc
AviraTR/Crypt.Agent.sbjaw
MAXmalware (ai score=86)
MicrosoftTrojan:Win32/Wacatac.D8!ml
ZoneAlarmTrojan.Win32.Zonidel.fgk
GDataGen:Variant.Razy.784829
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.Reputation.C4222546
BitDefenderThetaGen:NN.ZexaCO.34634.8uW@a41Khchi
ALYacGen:Variant.Razy.784829
MalwarebytesBackdoor.AveMaria
ESET-NOD32a variant of Win32/Kryptik.HHGP
TrendMicro-HouseCallTROJ_GEN.R002H0CKE20
RisingSpyware.AveMaria!8.108C2 (TFE:5:Mv6iUMtetfV)
SentinelOneStatic AI – Suspicious PE
FortinetW32/Kryptik.HHGP!tr
AVGWin32:RATX-gen [Trj]
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Generic/Trojan.63c

How to remove Razy.784829?

Razy.784829 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment