Malware

Razy.158303 removal tips

Malware Removal

The Razy.158303 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.158303 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Executed a process and injected code into it, probably while unpacking
  • Exhibits behavior characteristic of Nymaim malware
  • Checks the version of Bios, possibly for anti-virtualization
  • Zeus P2P (Banking Trojan)
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

haqgcyzzrhyr.com
zbbmvgh.pw
ytlbpbx.pw
bwaxqcmrtt.com
pxnwtuxo.in
iwfbmdvftib.in
zzliuvhql.pw
opocob.pw
lcbijis.com
ngsqymfv.com
aaslu.pw
tjrcewdd.net
jwhjluugqzga.net
fsduv.net
kojntkaldbiv.com

How to determine Razy.158303?


File Info:

crc32: 19708ADA
md5: 8116c26cb424e0566749ebf2c0fccf2d
name: 8116C26CB424E0566749EBF2C0FCCF2D.mlw
sha1: cf171706b94aff7b2029f156ccfdc400226a9826
sha256: f8a111c284f505ed9d761dac64d12cbbeee13ece5afa43eb5ca2e886caf61eb0
sha512: 4d0149a88fb8f3089c36230527b180d9203a6a36ae69299341879421d8ea7b5a2ed475915ece784aa779d39c20c99d7351c426176822f936657e57adf5bdd8c3
ssdeep: 12288:VCwJ0lOzH+Z0ZyhZQT/WiwCKDV0V1Z3Dzq:YwQZxhZQT/WiJi6V1Z3Dz
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Razy.158303 also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Nymaim.143
MicroWorld-eScanGen:Variant.Razy.158303
FireEyeGeneric.mg.8116c26cb424e056
ALYacGen:Variant.Razy.158303
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan-Downloader ( 004d4b861 )
BitDefenderGen:Variant.Razy.158303
K7GWTrojan-Downloader ( 004d4b861 )
Cybereasonmalicious.cb424e
BitDefenderThetaGen:NN.ZexaF.34804.QqW@aOt0@yai
CyrenW32/Trojan.INKC-3806
SymantecPacked.Generic.546
TrendMicro-HouseCallTROJ_NYMAIM.SMR2
AvastWin32:Rootkit-gen [Rtk]
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Nymaim.enskzb
AegisLabTrojan.Win32.Generic.4!c
TencentMalware.Win32.Gencirc.10bb85a6
Ad-AwareGen:Variant.Razy.158303
EmsisoftGen:Variant.Razy.158303 (B)
ComodoMalware@#5k14tks5oxin
F-SecureHeuristic.HEUR/AGEN.1117617
ZillyaTrojan.Nymaim.Win32.1815
TrendMicroTROJ_NYMAIM.SMR2
McAfee-GW-EditionBehavesLike.Win32.Generic.jm
SophosMal/Generic-S
IkarusTrojan-Downloader.Win32.Nymaim
JiangminTrojan.Nymaim.bza
eGambitUnsafe.AI_Score_97%
AviraHEUR/AGEN.1117617
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.Nymaim
MicrosoftTrojan:Win32/Azorult!ml
ArcabitTrojan.Razy.D26A5F
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Razy.158303
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C1900964
Acronissuspicious
McAfeeTrojan-FLPA!8116C26CB424
VBA32Trojan.Regsup
MalwarebytesTrojan.Nymaim.Generic
PandaTrj/GdSda.A
APEXMalicious
ESET-NOD32Win32/TrojanDownloader.Nymaim.BA
RisingDownloader.Silcon!8.2D0A (RDMK:cmRtazrcEw6927SUCUBhPVWIoHX6)
YandexTrojan.Nymaim!AtN3N0YKsto
SentinelOneStatic AI – Malicious PE – Downloader
FortinetW32/Nymaim.354F!tr
AVGWin32:Rootkit-gen [Rtk]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM20.1.0FE2.Malware.Gen

How to remove Razy.158303?

Razy.158303 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment