Malware

About “Razy.808750” infection

Malware Removal

The Razy.808750 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.808750 virus can do?

  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Code injection with CreateRemoteThread in a remote process
  • Tries to unhook or modify Windows functions monitored by Cuckoo

Related domains:

z.whorecord.xyz
ilo.brenz.pl
a.tomx.xyz
bjyhfk.com
ant.trenz.pl
zpnbmo.com
eyyyho.com
mtembs.com
cbajga.com
khamga.com
jscezv.com
mvwoao.com
keesef.com
ueinsm.com
oirubr.com
urekfa.com
ibjysz.com
anaesm.com
ojxahb.com
eevfug.com
ejsuio.com
uueuyh.com
mkogue.com
ilqemj.com
wqqobc.com
smvueh.com
doraoy.com
jjryop.com
xibixs.com
zwyeap.com
lmvlfm.com
ocnejd.com
gyrayg.com
btgknn.com
xwfiio.com
uvecke.com
xioumv.com
fuyerb.com
mayyjl.com
aoozhd.com

How to determine Razy.808750?


File Info:

crc32: E56334C6
md5: e970794be25b27a9246e5e0db49f9a45
name: E970794BE25B27A9246E5E0DB49F9A45.mlw
sha1: d041c4d2567811917fa707c37cf813e077222196
sha256: e5abfe17a2932936a78f07bab321d3f1adddaf7b01f1b721cc031300cd695d79
sha512: 1497b24668729bccfc149f247dbd933d06c8efe756eb37beb4f494bf179c22b2e78e38b93f1b46ed7e80a763af95e7b79e933ba66439db7b532877a4e42fab44
ssdeep: 1536:K5MDWfdUlwpu7eJmun7vIzmQWgyX6X33xz4fP4OTvs9rYfd/uCAGbv5kIOdt:Kiq2lwpu7kFbMm4XHh8GrNpGbvrO3
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: PinatioProject 2014-2015
InternalName: Cheat PB By Rahma ( Masih Percobaan )
FileVersion: 1.00
CompanyName: PinatioProject Injector
LegalTrademarks: PinatioProject Resallerx2122
ProductName: Injector Trial Update
ProductVersion: 1.00
FileDescription: PinatioProjectx2122
OriginalFilename: Cheat PB By Rahma ( Masih Percobaan ).exe

Razy.808750 also known as:

LionicTrojan.Win32.Zbot.4!c
DrWebTrojan.Packed.1895
ClamAVWin.Tool.Johnnie-6793850-0
CAT-QuickHealW32.Virut.G
ALYacGen:Variant.Razy.808750
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7GWVirus ( f10002001 )
K7AntiVirusVirus ( f10002001 )
CyrenW32/Virut.R.gen!Eldorado
SymantecW32.Virut.CF
ESET-NOD32a variant of Win32/Virut.NHD
APEXMalicious
AvastFileRepMalware
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Inject.aiswr
BitDefenderGen:Variant.Razy.808750
NANO-AntivirusVirus.Win32.Virut.hpeg
MicroWorld-eScanGen:Variant.Razy.808750
TencentWin32.Virus.Virut.Alie
Ad-AwareGen:Variant.Razy.808750
SophosMal/Generic-S
ComodoPacked.Win32.MUPX.Gen@24tbus
BitDefenderThetaAI:Packer.2CE776231F
TrendMicroPE_VIRUX.S-3
McAfee-GW-EditionBehavesLike.Win32.Generic.lc
FireEyeGeneric.mg.e970794be25b27a9
EmsisoftGen:Variant.Razy.808750 (B)
SentinelOneStatic AI – Malicious PE
AviraW32/Virut.Gen
Antiy-AVLTrojan/Generic.ASVirus.2F
KingsoftWin32.Infected.Virut.sr.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Razy.DC572E
GDataGen:Variant.Razy.808750
TACHYONVirus/W32.Virut.Gen
AhnLab-V3Win32/Virut.F
MAXmalware (ai score=83)
VBA32Virus.Virut.14
PandaTrj/CI.A
TrendMicro-HouseCallPE_VIRUX.S-3
YandexTrojan.GenAsa!3MFsSPYuEbQ
IkarusTrojan.Win32.Genome
FortinetW32/Virut.CE
AVGFileRepMalware

How to remove Razy.808750?

Razy.808750 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment