Malware

Razy.524931 removal

Malware Removal

The Razy.524931 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.524931 virus can do?

  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Sniffs keystrokes
  • Interacts with known DarkComet registry keys
  • Creates known Fynloski/DarkComet mutexes

Related domains:

z.whorecord.xyz
a.tomx.xyz
69848294.no-ip.org

How to determine Razy.524931?


File Info:

crc32: 086AF8A4
md5: 74369cd1ca77228eb24bea516574ceae
name: 74369CD1CA77228EB24BEA516574CEAE.mlw
sha1: 8144ced3e4bb3eee9731650573cdaa3bb9256fac
sha256: 808329fbc8e4c007fa11d9ef61c8794b932b78bd25a3829cf5996f83a1a892d9
sha512: e366d13c26cf67984d4662072ed2ddeeb53ec9d9f3f0246c52298896d01349feda72f0ee04cbbca2b7f9be2d390a90295bea3f2c1fd9ed3f7da8de33298b5fa3
ssdeep: 24576:vyJdb/BqfMLtVxiBuRRaplAXF07W2vn+Kx6NJfKiAax:v2l/BqfMzwBmarMAlvyNJfBzx
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2005-2012 Simon Tatham
Assembly Version: 0.62.0.0
InternalName: xe0axe47xe2dxe04xe42xe01xe41xe25xe15.exe
FileVersion: 0.62.0.0
CompanyName: Simon Tatham
LegalTrademarks: PuTTY3
Comments: PuTTY2
ProductName: 0.0.62.0
ProductVersion: 0.62.0.0
FileDescription: PuTTY
OriginalFilename: xe0axe47xe2dxe04xe42xe01xe41xe25xe15.exe

Razy.524931 also known as:

K7AntiVirusTrojan ( 700000121 )
LionicTrojan.Win32.Generic.4!c
DrWebWin32.HLLW.Autoruner.25074
CynetMalicious (score: 99)
ALYacGen:Variant.Razy.524931
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 700000121 )
Cybereasonmalicious.1ca772
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.ATR
APEXMalicious
AvastMSIL:Agent-YR [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.524931
NANO-AntivirusTrojan.Win32.Dapato.dcjjpa
MicroWorld-eScanGen:Variant.Razy.524931
TencentWin32.Trojan.Generic.bsag
Ad-AwareGen:Variant.Razy.524931
SophosMal/Generic-S
ComodoMalware@#3jb7s4c6yz4gw
BitDefenderThetaAI:Packer.6B1E376D1F
TrendMicroTROJ_GEN.R002C0PKK21
McAfee-GW-EditionGenericRXHS-WZ!74369CD1CA77
FireEyeGeneric.mg.74369cd1ca77228e
EmsisoftGen:Variant.Razy.524931 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.MSIL.Gen
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftBackdoor:Win32/Fynloski.M
GDataGen:Variant.Razy.524931
McAfeeGenericRXHS-WZ!74369CD1CA77
MAXmalware (ai score=80)
TrendMicro-HouseCallTROJ_GEN.R002C0PKK21
IkarusTrojan.Win32.Spy
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Injector.KYX!tr
AVGMSIL:Agent-YR [Trj]
Paloaltogeneric.ml

How to remove Razy.524931?

Razy.524931 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment