Malware

Should I remove “Razy.568458”?

Malware Removal

The Razy.568458 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.568458 virus can do?

  • Presents an Authenticode digital signature
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Razy.568458?


File Info:

crc32: D5B80523
md5: 60afdec227fef5d33ef5a05dd5c6bb54
name: share_01.exe
sha1: 64bc6d0bef2b50b11153e38a03789076dbd07ee8
sha256: 2e17c6575f942468770b00b39533f7c8d320202ba043fee00839d22a9aa49e13
sha512: ee549a5e189d9ce8680cfc40f2950b93acab487999538e9efdbbb60c93c65cf54a1419cb28ed08b3b95428f4760f6f327e16f03e465188814b41e18fee647fa4
ssdeep: 12288:pYR4Rd2pr7jgXerv4LFdOX5Y7lamg7FEYeFw0ajQ8eW:3daAXEwO8Vg7FEYuw0uQ8eW
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2019 x8c46x9ea6x7b14x8bb0 .Inc
InternalName: ADManage.exe
FileVersion: 2019.3.25.33
CompanyName: TODO:
ProductName: x70edx70b9x65b0x95fb
ProductVersion: 2019.3.25.33
FileDescription: x70edx70b9x65b0x95fb
OriginalFilename: ADManage.exe
Translation: 0x0804 0x04b0

Razy.568458 also known as:

MicroWorld-eScanGen:Variant.Razy.568458
FireEyeGen:Variant.Razy.568458
McAfeeArtemis!60AFDEC227FE
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan-Downloader ( 00554ed11 )
BitDefenderGen:Variant.Razy.568458
K7GWTrojan-Downloader ( 00554ed11 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Adload.NUQ
TrendMicro-HouseCallTROJ_GEN.R02CH0CLD19
AvastWin32:TrojanX-gen [Trj]
GDataGen:Variant.Razy.568458
Kasperskynot-a-virus:HEUR:AdWare.Win32.ComponentBased.gen
AlibabaTrojanDownloader:Win32/Adload.2aa6b5af
RisingAdware.Agent!1.BA2F (CLASSIC)
Ad-AwareGen:Variant.Razy.568458
SophosADManage (PUA)
ComodoApplicUnwnt@#1a5g41x35p34m
F-SecureTrojan.TR/Dldr.Adload.apvqm
ZillyaDownloader.Adload.Win32.91485
McAfee-GW-EditionArtemis!PUP
EmsisoftGen:Variant.Razy.568458 (B)
CyrenW32/Trojan.UHVP-7917
JiangminAdWare.ComponentBased.w
AviraTR/Dldr.Adload.apvqm
Antiy-AVLGrayWare[AdWare]/Win32.ComponentBased
ArcabitTrojan.Razy.D8AC8A
AhnLab-V3PUP/Win32.AdLoad.C3637472
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.ComponentBased.gen
MicrosoftPUA:Win32/CoinMiner
VBA32BScope.Adware.ComponentBased
ALYacGen:Variant.Razy.568458
MAXmalware (ai score=100)
CylanceUnsafe
TencentMalware.Win32.Gencirc.10b62ad2
YandexPUA.ComponentBased!
IkarusTrojan-Downloader.Win32.Adload
eGambitUnsafe.AI_Score_99%
FortinetW32/Adload.NUJ!tr.dldr
AVGWin32:TrojanX-gen [Trj]
Qihoo-360Win32/Trojan.fc8

How to remove Razy.568458?

Razy.568458 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment