Malware

Razy.945356 (B) removal tips

Malware Removal

The Razy.945356 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.945356 (B) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Unconventionial language used in binary resources: Spanish (Modern)
  • The binary likely contains encrypted or compressed data.
  • Checks for the presence of known windows from debuggers and forensic tools
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • The following process appear to have been packed with Themida: 9E1F914AE1DCA0A8C42F5CF0DF19D98F.mlw
  • Network activity detected but not expressed in API logs
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

How to determine Razy.945356 (B)?


File Info:

crc32: 5AFB3F6E
md5: 9e1f914ae1dca0a8c42f5cf0df19d98f
name: 9E1F914AE1DCA0A8C42F5CF0DF19D98F.mlw
sha1: 548574f8717f27d94e1534418e0452538aa621fb
sha256: 59619d957fc88a2c7f7e7b6abcd25e3311f81e55a51d8cf2af5d975a1e36a4f0
sha512: 3639db1433428ff8c0ca4d0e79dd5542d96f305f966f65ea97d48509e555ac5028a4021521e8659b35bbe5c4c6d35551d2badc924f0d6c9864d422b88363f995
ssdeep: 49152:NKoWP2YBBRTum8zieu7+KZmW/YXAb3P5KO76XOi/f:coWP2YByOeW+KZm1wb/5v5Sf
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Implbits Software All rights reserved.
InternalName: HashTab.dll
FileVersion: 6.0.0.0
CompanyName: Implbits Software
ProductName: HashTab
ProductVersion: 6.0.0.0
FileDescription: HashTab File Hash Shell Extension
OriginalFilename: HashTab.dll
Translation: 0x0409 0x04e4

Razy.945356 (B) also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (W)
Cybereasonmalicious.8717f2
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastFileRepMalware
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Razy.945356
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanGen:Variant.Razy.945356
Ad-AwareGen:Variant.Razy.945356
McAfee-GW-EditionBehavesLike.Win32.Dropper.vc
FireEyeGeneric.mg.9e1f914ae1dca0a8
EmsisoftGen:Variant.Razy.945356 (B)
SentinelOneStatic AI – Malicious PE
MicrosoftTrojan:Win32/Tnega!ml
GridinsoftTrojan.Heur!.032100A1
GDataGen:Variant.Razy.945356
McAfeeArtemis!9E1F914AE1DC
MAXmalware (ai score=81)
VBA32BScope.Trojan.Wacatac
TrendMicro-HouseCallTROJ_GEN.R002H09IQ21
RisingTrojan.Generic@ML.86 (RDML:XnSJZgzCR3AdbWM3XX62ww)
IkarusTrojan.Win32.Generic
FortinetW32/PossibleThreat
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Razy.945356 (B)?

Razy.945356 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment