Malware

What is “Razy.140006”?

Malware Removal

The Razy.140006 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.140006 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • The binary likely contains encrypted or compressed data.
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Razy.140006?


File Info:

crc32: 32C34814
md5: bdde9999b3f2420746b96b943610b231
name: BDDE9999B3F2420746B96B943610B231.mlw
sha1: 6264099ebcb30e020921ea9432b49de3f2aabdde
sha256: 1297f1dcdcf475efebafde0f345fce2da5a006f0817b96003025674b5e36b84b
sha512: c5868f3521a9c2fe8f3d0b84a518dba72afe96333f382fbbf055d76cd72c6f786500ee38d97aa9064c17d7265b5cfa5246226acf3a63e4b94c53060c16624e83
ssdeep: 1536:eUkp9s5Zk/ja8giYKPdzgSyeP4ZtYBphBFR4:eiZZNSPNgSyeQGDR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Razy.140006 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005137001 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Sphinx.2
CynetMalicious (score: 100)
CAT-QuickHealRansom.Exxroute.A3
ALYacGen:Variant.Razy.140006
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Spora.84b16846
K7GWTrojan ( 005137001 )
Cybereasonmalicious.9b3f24
CyrenW32/Spora.D.gen!Eldorado
SymantecPacked.Generic.493
ESET-NOD32a variant of Win32/Kryptik.FOYF
APEXMalicious
AvastWin32:Filecoder-AY [Trj]
ClamAVWin.Ransomware.Razy-6903617-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.140006
NANO-AntivirusTrojan.Win32.Sphinx.evplqm
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
MicroWorld-eScanGen:Variant.Razy.140006
TencentMalware.Win32.Gencirc.10b67424
Ad-AwareGen:Variant.Razy.140006
SophosML/PE-A + Mal/Elenoocka-E
ComodoTrojWare.Win32.Crypt.C@7vajd0
BitDefenderThetaGen:NN.ZexaF.34686.gmW@a4MMCZl
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CERBER.SM37
McAfee-GW-EditionBehavesLike.Win32.Autorun.cm
FireEyeGeneric.mg.bdde9999b3f24207
EmsisoftGen:Variant.Razy.140006 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Spora.qs
AviraHEUR/AGEN.1116786
eGambitUnsafe.AI_Score_98%
MicrosoftRansom:Win32/Spora.A
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Variant.Razy.140006
AhnLab-V3Trojan/Win32.Spora.R195937
Acronissuspicious
McAfeeRansomware-FMJ!BDDE9999B3F2
MAXmalware (ai score=100)
VBA32BScope.TrojanPSW.Sphinx
MalwarebytesCerber.Ransom.Encrypt.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_CERBER.SM37
RisingRansom.Cerber!8.3058 (CLOUD)
YandexTrojan.GenAsa!chThSBOeGTc
IkarusTrojan-Ransom.Cerber
FortinetW32/Kryptik.FOYF!tr
AVGWin32:Filecoder-AY [Trj]
Paloaltogeneric.ml

How to remove Razy.140006?

Razy.140006 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment