Malware

About “Razy.553929 (B)” infection

Malware Removal

The Razy.553929 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.553929 (B) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.

How to determine Razy.553929 (B)?


File Info:

crc32: 3890EACD
md5: 0fb8365981bde106318c9af0ba92ea36
name: cloudnet.exe
sha1: 80b23fa1298d65d30fdaaf075aceb197a718e698
sha256: ef7dc9704d13f438cceead5fa373f79e1393952c87fed1732f784e21351aef1b
sha512: 74b0fc4e9360dd1d585eed41bc627508de5331ef03156aa9d4a53b5b723df70e866a02ed66c1dc1bd857aed5dbb343e1c2ddbdcb7356777a27763b5ec5219d5c
ssdeep: 12288:OuJBX59liKca7zAcWQzuCaO+PzQoBIeuFnU9+S:XJf9liKD7WQyNzQoyefAS
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2017
InternalName: cloudnet.exe
FileVersion: 7.2.1.1
CompanyName: EpicNet Inc.
ProductName: EpicNet Cloud Office
ProductVersion: 7.2.1.1
FileDescription: Cloud Net
OriginalFilename: cloudnet.exe
Translation: 0x0409 0x04b0

Razy.553929 (B) also known as:

MicroWorld-eScanGen:Variant.Razy.553929
FireEyeGeneric.mg.0fb8365981bde106
CAT-QuickHealTrojan.Mauvaise.S3449555
Qihoo-360HEUR/QVM20.1.A44D.Malware.Gen
McAfeeTrojan-FQGO!0FB8365981BD
MalwarebytesTrojan.BitCoinMiner
K7AntiVirusTrojan ( 005115a11 )
BitDefenderGen:Variant.Razy.553929
K7GWTrojan ( 005115a11 )
CrowdStrikewin/malicious_confidence_90% (D)
ArcabitTrojan.Razy.D873C9
Invinceaheuristic
CyrenW32/Glupteba.A.gen!Eldorado
ESET-NOD32a variant of Win32/Glupteba.BC
APEXMalicious
ClamAVWin.Dropper.Glupteba-6973164-0
GDataGen:Variant.Razy.553929
KasperskyHEUR:Trojan-Proxy.Win32.Glupteba.gen
SUPERAntiSpywareHack.Tool/Gen-BitCoinMiner
RisingTrojan.Glupteba!1.BC88 (CLASSIC)
Ad-AwareGen:Variant.Razy.553929
SophosTroj/Glupteba-M
ComodoTrojWare.Win32.Glupteba.BC@82zlxv
F-SecureTrojan.TR/Crypt.XPACK.Gen2
DrWebTrojan.Proxy2.1436
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
EmsisoftGen:Variant.Razy.553929 (B)
SentinelOneDFI – Malicious PE
F-ProtW32/Glupteba.A.gen!Eldorado
JiangminTrojanProxy.Glupteba.adt
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.Gen2
Antiy-AVLTrojan/Win32.Glupteba.a
MicrosoftTrojan:Win32/Glupteba
Endgamemalicious (high confidence)
ZoneAlarmHEUR:Trojan-Proxy.Win32.Glupteba.gen
AhnLab-V3Trojan/Win32.SmearPasse.R247805
Acronissuspicious
ALYacGen:Variant.Razy.553929
MAXmalware (ai score=80)
VBA32BScope.TrojanProxy.Glupteba
CylanceUnsafe
PandaTrj/Genetic.gen
IkarusTrojan.Win32.Glupteba
FortinetW32/Glupteba.B!tr
AVGWin32:CrypterX-gen [Trj]
Cybereasonmalicious.981bde
AvastWin32:CrypterX-gen [Trj]
MaxSecureTrojan.Win32.Glupteba

How to remove Razy.553929 (B)?

Razy.553929 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment