Malware

Should I remove “Razy.579985”?

Malware Removal

The Razy.579985 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.579985 virus can do?

  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Razy.579985?


File Info:

crc32: 44CFAB4B
md5: 09fdbf24c8d42abd1d55d7655e80f406
name: 09FDBF24C8D42ABD1D55D7655E80F406.mlw
sha1: 6ce5c70735189999f96054fab8f5acb0cf489de0
sha256: 4d2cb5ada01391973bc098b3de04e0b9d4e5c76702f75b71f91e69ae2d882f43
sha512: 36f601d8ca21dc1abdd707a3b0feca89cd3bb23dcbdee393fcec201f274804c8eb3f7314dca21cb7f58c8e4db115869dc1e75f8369a46c101920422ea334d9f1
ssdeep: 49152:QQQWCXUyo2XAC7ETBptmICobx8hiHJGLVXg/eZ1QDLGvtGYGLotvk+HK+:DQWCE0XF+9mMx8skLN7AwrG6vDHK+
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

ProductVersion: 2.0.2021.1105
FileVersion: 2.0.2021.1105
Comments:
FileDescription: Snapshotx7b80x6613x6c49x5316x5de5x5177
Translation: 0x0804 0x04b0

Razy.579985 also known as:

ALYacGen:Variant.Razy.579985
CylanceUnsafe
Cybereasonmalicious.4c8d42
AvastWin32:Paleworm-E [Wrm]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.579985
NANO-AntivirusTrojan.Win32.Boigy.gefbnv
MicroWorld-eScanGen:Variant.Razy.579985
BitDefenderThetaGen:NN.ZexaF.34266.im0@a0XlIDgb
FireEyeGeneric.mg.09fdbf24c8d42abd
EmsisoftGen:Variant.Razy.579985 (B)
SentinelOneStatic AI – Suspicious PE
JiangminAdWare.Generic.tpkh
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitTrojan.Razy.D8D991
GDataGen:Variant.Razy.579985
MAXmalware (ai score=86)
VBA32BScope.Trojan.Bitrep
RisingMalware.Heuristic!ET#86% (RDMK:cmRtazpil6bByjqC3+aaBEE1ui3k)
AVGWin32:Paleworm-E [Wrm]

How to remove Razy.579985?

Razy.579985 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment