Categories: Malware

What is “Razy.524966”?

The Razy.524966 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.524966 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Razy.524966?


File Info:

crc32: F77FF662md5: 31b9f27f2614e18397b6cebd9c01cf50name: 31B9F27F2614E18397B6CEBD9C01CF50.mlwsha1: 6e1c61014b55340eb20cd10b66d674166f6e63d5sha256: 9c62466076359c500aeb1c8f0f61afb80e67695f173e0ee6227c78df16cc3c15sha512: d5f4e81718e1d31e01e38a38c3fab0447e263e291a8fd3d8d7a1bafa5fcbc34ec397f6510b6d18009b96b99e497a9b465ab006220d9bf74c25d240d4b4e2b61assdeep: 1536:CzUHtgitOssPWAGPRlZ2Za2PZe++0qFTUTI98BdWDjauRbRXc4ruHM52d0CJCyk:C0tgFEf/F44++zU7YDmu5RXEd0Aktype: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Razy.524966 also known as:

K7AntiVirus EmailWorm ( 003247681 )
Elastic malicious (high confidence)
DrWeb Trojan.Necurs.97
Cynet Malicious (score: 100)
ALYac Gen:Variant.Razy.524966
Cylance Unsafe
Zillya Trojan.PornoAsset.Win32.4714
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_90% (D)
K7GW EmailWorm ( 003247681 )
Cybereason malicious.f2614e
Cyren W32/Trojan.JJQE-3056
Symantec Trojan.Ransomlock!g11
ESET-NOD32 Win32/Cridex.AA
APEX Malicious
Avast Win32:Crypt-NWI [Trj]
ClamAV Win.Ransomware.Zbot-9825405-0
Kaspersky UDS:DangerousObject.Multi.Generic
BitDefender Gen:Variant.Razy.524966
NANO-Antivirus Trojan.Win32.PornoAsset.bbugky
ViRobot Trojan.Win32.A.PornoAsset.100864.D
SUPERAntiSpyware Trojan.Agent/Gen-Ransom
MicroWorld-eScan Gen:Variant.Razy.524966
Tencent Malware.Win32.Gencirc.11bc56cb
Ad-Aware Gen:Variant.Razy.524966
Sophos ML/PE-A + Mal/ZboCheMan-D
Comodo TrojWare.Win32.Kryptik.AMMJ@4r4i67
BitDefenderTheta Gen:NN.ZexaF.34688.g4W@aWZ9UHci
VIPRE LooksLike.Win32.ZboCheman.a (v)
McAfee-GW-Edition BehavesLike.Win32.ZBot.nh
FireEye Generic.mg.31b9f27f2614e183
Emsisoft Gen:Variant.Razy.524966 (B)
SentinelOne Static AI – Malicious PE
Avira TR/Crypt.XPACK.Gen
eGambit Trojan.Generic
Antiy-AVL Trojan/Generic.ASMalwS.6AA43
Kingsoft Win32.Heur.KVM007.a.(kcloud)
Microsoft Worm:Win32/Cridex.E
Arcabit Trojan.Razy.D802A6
GData Gen:Variant.Razy.524966
AhnLab-V3 Trojan/Win32.PornoAsset.R38083
Acronis suspicious
McAfee PWS-Zbot.gen.anq
MAX malware (ai score=88)
VBA32 BScope.Worm.Cridex.2112
Panda Trj/Genetic.gen
Rising Ransom.PornoAsset!8.6AA (CLOUD)
Yandex Trojan.GenAsa!oTL/99c9n9M
Ikarus Trojan-Ransom.PornoAsset
Fortinet W32/ZeroAccess.B!tr
AVG Win32:Crypt-NWI [Trj]

How to remove Razy.524966?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

What is “Trojan.Generic.35791346”?

The Trojan.Generic.35791346 is considered dangerous by lots of security experts. When this infection is active,…

22 mins ago

Malware.AI.1480269634 removal tips

The Malware.AI.1480269634 is considered dangerous by lots of security experts. When this infection is active,…

22 mins ago

Adware.BrowseFox.305 removal

The Adware.BrowseFox.305 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Win32/AutoRun.VB.AUW (file analysis)

The Win32/AutoRun.VB.AUW is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

Trojan:Win64/Metasploit!pz removal guide

The Trojan:Win64/Metasploit!pz is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

What is “Win32/Agent_AGen.BLW”?

The Win32/Agent_AGen.BLW is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago