Malware

Razy.980085 removal guide

Malware Removal

The Razy.980085 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.980085 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Code injection with CreateRemoteThread in a remote process
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Razy.980085?


File Info:

crc32: 3B208305
md5: 1e8f9412591b4776085ea6236cc9a49d
name: 1E8F9412591B4776085EA6236CC9A49D.mlw
sha1: 9812e343bbe8e3255d693111d9521851225565ab
sha256: 1a2160ef85c45332d7ba369879f9db7783e9530b84cdcda0db08afe77cbf3c93
sha512: 07cd3093b133fcf3730bc53ecf92d89fb522f2e292eef09c58f06397a591f56d963a935cbd4abc8cfb8e58abbe22608e691c2d2985201c4ba122c653b4f7a72b
ssdeep: 3072:09d/XJ1hFQTbliFZfri0NY5K9HdzO5Sxf92j2gGwt+6iqh:09VXJ1hFGblSfq5K9HI5C92jhGwtf
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

Razy.980085 also known as:

K7AntiVirusTrojan ( 0052a44b1 )
LionicTrojan.Win32.Agent.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Nanocore.427
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.980085
CylanceUnsafe
ZillyaBackdoor.Agent.Win32.69335
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaBackdoor:MSIL/Injector.50930205
K7GWTrojan ( 0052a44b1 )
Cybereasonmalicious.2591b4
CyrenW32/Trojan.BWK.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.DNB
APEXMalicious
AvastWin32:RATX-gen [Trj]
ClamAVWin.Dropper.Nanocore-9903300-0
KasperskyHEUR:Backdoor.Win32.Agent.gen
BitDefenderGen:Variant.Razy.980085
NANO-AntivirusTrojan.Win32.Nanocore.fiogrf
MicroWorld-eScanGen:Variant.Razy.980085
TencentWin32.Trojan.Inject.Auto
Ad-AwareGen:Variant.Razy.980085
SophosMal/Generic-S
ComodoMalware@#2zx20uqmjustu
BitDefenderThetaGen:NN.ZemsilF.34236.Rm3@aiBbwBf
TrendMicroBKDR_ASDROP.SMZVP
McAfee-GW-EditionBehavesLike.Win32.Generic.jz
FireEyeGeneric.mg.1e8f9412591b4776
EmsisoftGen:Variant.Razy.980085 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Agent.ehm
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_99%
MicrosoftBackdoor:Win32/Bladabindi!ml
ZoneAlarmHEUR:Backdoor.Win32.Agent.gen
GDataGen:Variant.Razy.980085
AhnLab-V3Backdoor/Win.Asdrop.C4695696
McAfeeGenericRXFZ-DO!1E8F9412591B
MAXmalware (ai score=100)
VBA32Backdoor.Agent
MalwarebytesTrojan.MalPack.MSIL.Generic
PandaTrj/CI.A
TrendMicro-HouseCallBKDR_ASDROP.SMZVP
YandexTrojan.DR.Agent!IZb+05HWp1w
IkarusTrojan-Dropper.MSIL.Agent
FortinetMSIL/CoinMiner.SHS!tr
AVGWin32:RATX-gen [Trj]
Paloaltogeneric.ml

How to remove Razy.980085?

Razy.980085 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment