Malware

Razy.823296 (B) removal guide

Malware Removal

The Razy.823296 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.823296 (B) virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Razy.823296 (B)?


File Info:

crc32: DF4F7AB2
md5: 6490bfa0d8517e2607743d78458e640d
name: 6490BFA0D8517E2607743D78458E640D.mlw
sha1: a79ed4ecd0a013cc452594fd6c12862caee71c84
sha256: 84345fe9f9386970a43f103d2b67fdfaf2b63c10ef1116ff1be46d7183618ae0
sha512: 28154b58d22434104a5ee1aba19b8ebe5bcacc2ee34568dbf73aca1ebc24d939c0f19a8c4cc99f5ec420f43fc78dda3ef0c237e1ebf01550bb48b8b6c8adfc3d
ssdeep: 6144:1Ua+SGoAaVZSz58otQvkYRybhlyH053mXSLYp83RAhc3mbMFmv4RQx83ubpQXGB:+acoPitsHUtsH03
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: SearchProtocolHost.exe
FileVersion: 7.00.7600.16385 (win7_rtm.090713-1255)
CompanyName: Microsoft Corporation
ProductName: Windowsxae Search
ProductVersion: 7.00.7600.16385
FileDescription: Microsoft Windows Search Protocol Host
OriginalFilename: SearchProtocolHost.exe
Translation: 0x0409 0x04b0

Razy.823296 (B) also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.823296
FireEyeGeneric.mg.6490bfa0d8517e26
McAfeeGenericRXAA-AA!6490BFA0D851
CylanceUnsafe
SangforMalware
K7AntiVirusSpyware ( 0040f0131 )
BitDefenderGen:Variant.Razy.823296
K7GWSpyware ( 0040f0131 )
CrowdStrikewin/malicious_confidence_80% (D)
APEXMalicious
RisingTrojan.Kryptik!8.8 (TFE:2:ItOo6ejRx2)
Ad-AwareGen:Variant.Razy.823296
EmsisoftGen:Variant.Razy.823296 (B)
DrWebTrojan.Inject4.6464
McAfee-GW-EditionBehavesLike.Win32.ExtenBro.vt
SophosML/PE-A + Mal/EncPk-APV
SentinelOneStatic AI – Suspicious PE
MAXmalware (ai score=83)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Razy.DC9000
GDataGen:Variant.Razy.823296
CynetMalicious (score: 100)
BitDefenderThetaGen:NN.ZedlaF.34742.oM8@aax27Goi
ALYacGen:Variant.Razy.823296
VBA32BScope.Trojan.Gatak
FortinetW32/Kryptik.HDNN!tr

How to remove Razy.823296 (B)?

Razy.823296 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment