Malware

Razy.802946 information

Malware Removal

The Razy.802946 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.802946 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Razy.802946?


File Info:

crc32: F03ED3AF
md5: 136b75b273e9889814978d89a2f304be
name: 136B75B273E9889814978D89A2F304BE.mlw
sha1: e384d4b120d6bc072e5517ecfe30e17cea8b901e
sha256: 692aa8adc305de52bc4c784fc272aaf943b4f8128162b712b24444342078c751
sha512: 6272c00f4ebc3518cb98a4147c504078f7d675c4ba9c0e283b50986292c378970f445175ec187e86254f153708d570a7ce0261d54d4e265fbd6add919263326b
ssdeep: 3072:MU5X9BrbGJ/V37wg4MuYXV8zPYkY35oOp:lzlqPL94MVtv5x
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Razy.802946 also known as:

BkavW32.malware.sig1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.802946
ALYacTrojan.Agent.QakBot
CylanceUnsafe
SangforMalware
K7AntiVirusSpyware ( 0040f0131 )
BitDefenderGen:Variant.Razy.802946
K7GWSpyware ( 0040f0131 )
CyrenW32/Trojan.FSZ.gen!Eldorado
SymantecML.Attribute.HighConfidence
Paloaltogeneric.ml
KasperskyTrojan-Banker.Win32.RTM.fcr
AlibabaTrojanBanker:Win32/BankerX.23700079
ViRobotTrojan.Win32.Z.Qbot.2135808
AegisLabHacktool.Win32.Krap.lKMc
RisingTrojan.Generic@ML.87 (RDMK:kTmWwNJ1rEjgZFZ8iVV8/A)
Ad-AwareGen:Variant.Razy.802946
EmsisoftMalCert.A (A)
F-SecureTrojan.TR/AD.Qbot.wbnfj
DrWebBackDoor.Qbot.562
TrendMicroTrojan.Win32.MALREP.THLAOBO
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.136b75b273e98898
SophosML/PE-A + Mal/EncPk-APV
IkarusBackdoor.QBot
WebrootW32.Trojan.Qakbot
AviraTR/AD.Qbot.wbnfj
MAXmalware (ai score=83)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
KingsoftWin32.Troj.Banker.(kcloud)
MicrosoftTrojan:Win32/QakBot.MW!MTB
GridinsoftTrojan.Win32.Agent.oa
ArcabitTrojan.Razy.DC4082
ZoneAlarmTrojan-Banker.Win32.RTM.fcr
GDataGen:Variant.Razy.802946
CynetMalicious (score: 100)
McAfeeGenericRXAA-AA!136B75B273E9
VBA32BScope.Backdoor.Qbot
MalwarebytesBackdoor.Qbot
PandaTrj/CI.A
ESET-NOD32Win32/Qbot.CU
TrendMicro-HouseCallTrojan.Win32.MALREP.THLAOBO
YandexTrojan.Kryptik!T4aJTKZAwpw
SentinelOneStatic AI – Suspicious PE
FortinetW32/Kryptik.HDNN!tr
BitDefenderThetaGen:NN.ZedlaF.34688.cU6@aG9N2pdi
AVGWin32:DangerousSig [Trj]
AvastWin32:DangerousSig [Trj]
Qihoo-360Generic/Trojan.BO.c77

How to remove Razy.802946?

Razy.802946 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment