Malware

How to remove “Razy.16814”?

Malware Removal

The Razy.16814 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.16814 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Razy.16814?


File Info:

crc32: 707A74F1
md5: 59df854338a5958d339a9b1f6a8c59c2
name: 59DF854338A5958D339A9B1F6A8C59C2.mlw
sha1: 8d8340bc1d2961543d4f60c328e908949e4d20e3
sha256: 20d625a6e8f9b421d233c6f4e8ce55b2d5ccb32d719840cf32dce7127e34cfa6
sha512: 3b6109ec022a4141b6c11f683dbaa5a25e470f3e1a81d46409dfb3c4a1908b37e2efcf027340f98021210dd24c402e3cf3ff1ebb2584d18dad7469b200cea385
ssdeep: 768:MRzEfwAOG+03o/qGlkSzogOAiKXl1rPbtIMzBmyJ/v9jJ9dT8k429T:UIo5G+03UqGpHSS/SKBmyV9N78kl9
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: Server.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: Server.exe

Razy.16814 also known as:

K7AntiVirusTrojan ( 0053564e1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.16814
CylanceUnsafe
SangforSuspicious.Win32.Razy.16814
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 004b89ab1 )
Cybereasonmalicious.338a59
CyrenW32/MSIL_Troj.FT.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.JELLFQP
APEXMalicious
AvastWin32:Malware-gen
BitDefenderGen:Variant.Razy.16814
NANO-AntivirusTrojan.Win32.Buzy.efqime
MicroWorld-eScanGen:Variant.Razy.16814
TencentWin32.Trojan.Buzy.Szch
Ad-AwareGen:Variant.Razy.16814
SophosMal/Generic-S
ComodoMalware@#3aczfst9n4380
BitDefenderThetaGen:NN.ZemsilF.34294.dm0@aqtoHCo
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.qh
FireEyeGeneric.mg.59df854338a5958d
EmsisoftGen:Variant.Razy.16814 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Malware.Heur
AviraHEUR/AGEN.1124815
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Wacatac.B!ml
SUPERAntiSpywareTrojan.Agent/Generic
GDataGen:Variant.Razy.16814
Acronissuspicious
McAfeeGenericRXIH-EF!59DF854338A5
MAXmalware (ai score=80)
MalwarebytesTrojan.Agent
YandexTrojan.Agent!j3oCdSXTvvA
IkarusTrojan-Dropper.MSIL.Small
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Razy.16814?

Razy.16814 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment