Malware

About “Razy.869272” infection

Malware Removal

The Razy.869272 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.869272 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The executable is compressed using UPX
  • Attempts to create or modify system certificates

Related domains:

user.xunfss.com

How to determine Razy.869272?


File Info:

crc32: 48066B9E
md5: ff323f235c957f6c53a21ad8483e8595
name: FF323F235C957F6C53A21AD8483E8595.mlw
sha1: b9324c9ded9e5378ce4f58cfb96b4bb3380a6237
sha256: e3f4697b60bbece982a58703b7c64c70106566a645e066b7cd79c4df8e14b759
sha512: 5228a3a42241e1afea0eb526f240d7a9556bcbab0177986cdc28a43ded2c1e955e81d9b4f1e841280bf4e5f520997a260c713bb0b4a9e49ec0ccef720429b85e
ssdeep: 3072:3fKVxio9ICSvdw6zZ+TmEqFl2LKD+KwtK:3Do9KuecCJ2Bt
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: x6700x65b0x5730x5740
FileVersion: 1.00
CompanyName: 1024
ProductName: x6700x65b0x5730x5740
ProductVersion: 1.00
FileDescription:
OriginalFilename: x6700x65b0x5730x5740.exe
Translation: 0x0804 0x04b0

Razy.869272 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderGen:Variant.Razy.869272
Cybereasonmalicious.ded9e5
APEXMalicious
CynetMalicious (score: 100)
MicroWorld-eScanGen:Variant.Razy.869272
Ad-AwareGen:Variant.Razy.869272
SophosGeneric ML PUA (PUA)
BitDefenderThetaGen:NN.ZevbaCO.34690.nmKfayaUSBbb
FireEyeGeneric.mg.ff323f235c957f6c
EmsisoftGen:Variant.Razy.869272 (B)
SentinelOneStatic AI – Suspicious PE
ArcabitTrojan.Razy.DD4398
GDataGen:Variant.Razy.869272
MAXmalware (ai score=86)
MalwarebytesMalware.AI.1442062647
TrendMicro-HouseCallTROJ_GEN.R005H09EF21
RisingMalware.Heuristic!ET#84% (RDMK:cmRtazrNUhKYI8RcmlScLmRa1a8i)
FortinetPossibleThreat.PALLAS.H

How to remove Razy.869272?

Razy.869272 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment