Malware

Razy.816352 (file analysis)

Malware Removal

The Razy.816352 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.816352 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup

How to determine Razy.816352?


File Info:

crc32: 33AA0C1C
md5: f46ed8ba6212217e503dd11b66cc9da0
name: F46ED8BA6212217E503DD11B66CC9DA0.mlw
sha1: b9ac7860f2c469bf94624bd24703243c11b0ad8d
sha256: 3331d6e65f596dfaff9bc2547e2d9e7c1e4fc1f108a7a7bb8a33a0dc0aa78be6
sha512: c1c915b306ece7f03ff8ca983a5656c0ecb6e6e20b0854e86aaea93fad9b6ec1931e511e7d3de4221160d8adf6135f509e731d51edcf59fa608f4509cf052cbe
ssdeep: 6144:8yvLH5hV0pO9Rr9c3ZPQFP3bOIOTBCxh+:dbVQO9Tc2FTOIOTcH+
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Razy.816352 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebBackDoor.Qbot.568
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.816352
CylanceUnsafe
ZillyaTrojan.Qbot.Win32.12562
CrowdStrikewin/malicious_confidence_90% (W)
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Qbot.CV
APEXMalicious
AvastWin32:BankerX-gen [Trj]
KasperskyTrojan-Banker.Win32.Qbot.zvi
BitDefenderGen:Variant.Razy.816352
NANO-AntivirusTrojan.Win32.Qbot.iebbjx
MicroWorld-eScanGen:Variant.Razy.816352
TencentMalware.Win32.Gencirc.10ce3398
Ad-AwareGen:Variant.Razy.816352
SophosML/PE-A
BitDefenderThetaGen:NN.ZedlaF.34608.mu5@aihYfff
McAfee-GW-EditionBehavesLike.Win32.Dropper.dh
FireEyeGeneric.mg.f46ed8ba6212217e
EmsisoftGen:Variant.Razy.816352 (B)
AviraHEUR/AGEN.1140594
MicrosoftTrojan:Win32/Qakbot.GA!MTB
GDataGen:Variant.Razy.816352
AhnLab-V3Trojan/Win32.Qakbot.C4265398
McAfeeW32/PinkSbot-HP!F46ED8BA6212
MAXmalware (ai score=88)
VBA32Backdoor.Qbot
MalwarebytesBackdoor.Qbot
PandaTrj/GdSda.A
RisingTrojan.Qbot!8.8A3 (TFE:dGZlOgTvrH67FkxyRQ)
IkarusBackdoor.QBot
MaxSecureTrojan.Malware.74264913.susgen
FortinetW32/Qbot.568!tr
AVGWin32:BankerX-gen [Trj]
Qihoo-360HEUR/QVM40.1.D63F.Malware.Gen

How to remove Razy.816352?

Razy.816352 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment