Malware

Razy.297599 removal guide

Malware Removal

The Razy.297599 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.297599 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • A possible cryptomining command was executed

Related domains:

z.whorecord.xyz
iplogger.org
a.tomx.xyz

How to determine Razy.297599?


File Info:

crc32: 662158F1
md5: c6c7b6cf39547cbda2cf61ace469fdb0
name: look.exe
sha1: a448222d89fd260ebaf5caf4f34c52c72101f54d
sha256: 43b4d3980b64d701a9e0fb05f4aeb19addf6a52bcb8043e5089f0dff7ce1a4b0
sha512: 739b7c80134785815d7170fca5cfd07d30fbd6e0eb0d3370b44f178af0a879bd983f340ca9a71cc50c7eb7427b85460aedf3bf2b2b01b4bad5ced7826b265fbb
ssdeep: 24576:ylu5fbL4OH50lVt7hUUFxnP0YQ7AUhwMltNNPq1iTi/Vu6btC3yBXmk/yKOy0Wx:ylzOHU7W4nrQZhwMltNdq1CE/mmyKOy
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2018
Assembly Version: 1.0.0.0
InternalName: PredatorTheMiner.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: PredatorTheMiner
ProductVersion: 1.0.0.0
FileDescription: PredatorTheMiner
OriginalFilename: PredatorTheMiner.exe

Razy.297599 also known as:

MicroWorld-eScanGen:Variant.Razy.297599
McAfeeGenericRXHA-WZ!C6C7B6CF3954
CylanceUnsafe
AegisLabTrojan.Win64.Miner.4!c
SangforMalware
BitDefenderGen:Variant.Razy.297599
Cybereasonmalicious.f39547
TrendMicroTROJ_GEN.R002C0PDK20
APEXMalicious
AvastWin32:XMRigMiner-V [Trj]
GDataGen:Variant.Razy.297599
KasperskyTrojan.Win64.Miner.bzb
AlibabaTrojan:MSIL/CoinMiner.f141510c
TencentWin64.Trojan.Miner.Taex
Ad-AwareGen:Variant.Razy.297599
EmsisoftGen:Variant.Razy.297599 (B)
F-SecureHeuristic.HEUR/AGEN.1130468
DrWebTrojan.MinerNET.1
Invinceaheuristic
McAfee-GW-EditionGenericRXHA-WZ!C6C7B6CF3954
MaxSecureTrojan.Malware.300983.susgen
FireEyeGeneric.mg.c6c7b6cf39547cbd
SophosXMRig Miner (PUA)
SentinelOneDFI – Malicious PE
AviraHEUR/AGEN.1130468
Endgamemalicious (high confidence)
ArcabitTrojan.Razy.D48A7F
ZoneAlarmTrojan.Win64.Miner.bzb
MicrosoftTrojan:Win32/CoinMiner.C!cl
VBA32Trojan.Win64.Miner
ALYacGen:Variant.Razy.297599
MAXmalware (ai score=84)
MalwarebytesTrojan.BitCoinMiner
ESET-NOD32a variant of MSIL/CoinMiner.ARR
TrendMicro-HouseCallTROJ_GEN.R002C0PDK20
RisingTrojan.IPLogger!1.B69D (CLOUD)
IkarusTrojan.MSIL.CoinMiner
eGambitUnsafe.AI_Score_100%
FortinetAdware/Miner
BitDefenderThetaGen:NN.ZemsilF.34106.yn0@amGK4sn
AVGWin32:XMRigMiner-V [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win64/Trojan.9d6

How to remove Razy.297599?

Razy.297599 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment