Malware

Razy.115986 removal guide

Malware Removal

The Razy.115986 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.115986 virus can do?

  • Creates RWX memory
  • Drops a binary and executes it
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

Related domains:

yak.zapto.org

How to determine Razy.115986?


File Info:

crc32: B9B52A18
md5: 233352d6c55b02fad14cec1959d27868
name: 233352D6C55B02FAD14CEC1959D27868.mlw
sha1: 641e4f9f2b84c6f18a8c46b578971e18dca9ee48
sha256: 1e4d7cb4b8a6bf0aeb1d5649b25d3e59385ebb3735d5789c35d802449f0a3e3e
sha512: 6cdbb0c8851c54baeb1d1fb9d2af4912fe10e0ae1d2230b5fed4a899d0b239e1ab04a554d2d2a4e1d1037f53868cd640f09ef61dbbf41e2ab6d2c0e19f980f8a
ssdeep: 3072:qUdrDyaEG27dHR3+j14MPce8bV/ihIe/e77:qUdrDFNIdgjOMN8bFihIe/s
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: Copyright xc2xa92016 Telerik
InternalName: Fiddler.exe
FileVersion: 4.6.2.3
CompanyName: Telerik
LegalTrademarks: Fiddlerxe2x201exa2
ProductName: Fiddler
ProductVersion: 4.6.2.3
FileDescription: Fiddler
OriginalFilename: Fiddler.exe
Translation: 0x0409 0x04b0

Razy.115986 also known as:

K7AntiVirusTrojan ( 005121ae1 )
Elasticmalicious (high confidence)
DrWebBackDoor.SpyBotNET.20
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.115986
CylanceUnsafe
SangforSuspicious.Win32.Zusy.101161
CrowdStrikewin/malicious_confidence_70% (D)
K7GWTrojan ( 005121ae1 )
Cybereasonmalicious.6c55b0
CyrenW32/MSIL_Kryptik.AXY.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Agent.AZM
APEXMalicious
AvastWin32:RATX-gen [Trj]
ClamAVWin.Dropper.LimeRAT-9776087-0
KasperskyHEUR:Trojan.MSIL.RRAT.gen
BitDefenderGen:Variant.Razy.115986
NANO-AntivirusTrojan.Win32.AtomicRat.exwzxg
MicroWorld-eScanGen:Variant.Razy.115986
TencentMsil.Trojan.Rrat.Hoel
Ad-AwareGen:Variant.Razy.115986
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34266.iq0@a4z!gnei
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXML-ID!233352D6C55B
FireEyeGeneric.mg.233352d6c55b02fa
EmsisoftGen:Variant.Razy.115986 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1128452
eGambitTrojan.Generic
MicrosoftBackdoor:Win32/Bladabindi!ml
GDataGen:Variant.Razy.115986
AhnLab-V3Trojan/Win32.RL_Revenge.R353957
McAfeeGenericRXML-ID!233352D6C55B
MAXmalware (ai score=80)
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.100 (RDML:A5rCfytwwK1yLfgEvIPsuQ)
IkarusTrojan.MSIL.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.AZM!tr
AVGWin32:RATX-gen [Trj]
Paloaltogeneric.ml

How to remove Razy.115986?

Razy.115986 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment