Malware

Should I remove “Razy.506926”?

Malware Removal

The Razy.506926 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.506926 virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Razy.506926?


File Info:

crc32: A424E359
md5: 9b2f5cb09586ea0f5d29ecab6c04b7f2
name: 2dhgywbvppp.exe
sha1: 23375ca94f6385425d15b8a76337631c4c4641e4
sha256: 6f29c18bcf9b2995a65f4c599b7af6ba662b361f677ded3d43d072eb838d2d37
sha512: c904526418b19268ce77314dac6db9f7a8a38a0e4cdf67121a40eab9a6b2a4e50b35c1131ebcd5580d66039645cb4af4b66660cc03fb64822871dd64b0f23168
ssdeep: 6144:0JOSwvSnybC9IeKnCtRxTQ1aVEzG0R1hFq7M:0JOHvSaDCtRm1aVEzG0RjFqY
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: WerMgr
FileVersion: 10.0.17134.1 (WinBuild.160101.0800)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 10.0.17134.1
FileDescription: Windows Problem Reporting
OriginalFilename: WerMgr
Translation: 0x0409 0x04b0

Razy.506926 also known as:

MicroWorld-eScanGen:Variant.Razy.506926
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
ALYacGen:Variant.Razy.506926
CylanceUnsafe
K7AntiVirusSpyware ( 005489ea1 )
AlibabaTrojanPSW:MSIL/Cordis.04e2d312
K7GWSpyware ( 005489ea1 )
Cybereasonmalicious.09586e
Invinceaheuristic
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Spy.Agent.CEI
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-PSW.MSIL.Cordis.gen
BitDefenderGen:Variant.Razy.506926
SUPERAntiSpywareTrojan.Agent/Gen-PasswordStealer
Ad-AwareGen:Variant.Razy.506926
EmsisoftGen:Variant.Razy.506926 (B)
F-SecureTrojan.TR/Dropper.Gen
TrendMicroTROJ_GEN.R002C0PJC19
McAfee-GW-EditionGenericRXIA-PF!9B2F5CB09586
FortinetMSIL/Agent.RCD!tr.pws
FireEyeGeneric.mg.9b2f5cb09586ea0f
SophosMal/Generic-S
IkarusTrojan.MSIL.Spy
AviraTR/Dropper.Gen
MAXmalware (ai score=88)
Endgamemalicious (high confidence)
ArcabitTrojan.Razy.D7BC2E
AegisLabTrojan.MSIL.Cordis.i!c
ZoneAlarmHEUR:Trojan-PSW.MSIL.Cordis.gen
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Trojan/Win32.Agent.C2926564
Acronissuspicious
McAfeeGenericRXIA-PF!9B2F5CB09586
MalwarebytesSpyware.PasswordStealer
TrendMicro-HouseCallTROJ_GEN.R002C0PJC19
TencentMsil.Trojan-qqpass.Qqrob.Htmd
SentinelOneDFI – Malicious PE
GDataGen:Variant.Razy.506926
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Trojan.fc8

How to remove Razy.506926?

Razy.506926 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment