Malware

Razy.580153 (file analysis)

Malware Removal

The Razy.580153 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.580153 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Razy.580153?


File Info:

crc32: 9761BB6C
md5: 6bcb7eff52d6496cdf91bd321cf79b05
name: putty.exe
sha1: 6d6cb5f58b01cb21c87d33b27326003e889b0d6f
sha256: 331cb1a6d04185ce87d0a1ceca3231e38a9b5dc6ceb7204cdf1a7745e3f4387f
sha512: 0be735a97748122dc14158ba047704e46f4542506b9282102c63998698aba8a8a02cd0a9f4390eff827a483ef8aadb9e846083bc1c98abb76e021e9bfcfd208a
ssdeep: 24576:nnYO/xJrstd2u3SlTo259gy6Ym4ZrpdSdwwDtrm83z:9bst4u3n2PgTqpdSdvDtrm+z
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 1997-2019 Simon Tatham.
InternalName: PuTTY
FileVersion: Release 0.73 (with embedded help)
CompanyName: Simon Tatham
ProductName: PuTTY suite
ProductVersion: Release 0.73
FileDescription: SSH, Telnet and Rlogin client
OriginalFilename: PuTTY
Translation: 0x0809 0x04b0

Razy.580153 also known as:

MicroWorld-eScanGen:Variant.Razy.580153
McAfeeMalHeur-FAG!6BCB7EFF52D6
SangforMalware
BitDefenderGen:Variant.Razy.580153
K7GWTrojan ( 005662dc1 )
K7AntiVirusTrojan ( 005662dc1 )
ArcabitTrojan.Razy.D8DA39
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34110.cD0@aCF1Pwki
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Rozena.AMX.gen
APEXMalicious
RisingTrojan.Rozena!8.6D (RDMK:cmRtazrygrfee4Xwpmh6o2dZaMq1)
Ad-AwareGen:Variant.Razy.580153
EmsisoftGen:Variant.Razy.580153 (B)
F-SecureHeuristic.HEUR/AGEN.1125217
McAfee-GW-EditionBehavesLike.Win32.Backdoor.tc
FortinetW32/Shellter.C!tr
FireEyeGeneric.mg.6bcb7eff52d6496c
SophosMal/Shellter-C
IkarusTrojan.Win32.Rozena
AviraHEUR/AGEN.1125217
MAXmalware (ai score=86)
Endgamemalicious (high confidence)
MicrosoftTrojan:Win32/Meterpreter.gen!C
AhnLab-V3Malware/Win32.RL_Generic.R294493
Acronissuspicious
ALYacGen:Variant.Razy.580153
VBA32BScope.Trojan.Swrort
MalwarebytesTrojan.Rozena
PandaTrj/Genetic.gen
SentinelOneDFI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
GDataGen:Variant.Razy.580153
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.f52d64
AvastWin32:Evo-gen [Susp]
Qihoo-360HEUR/QVM10.1.54A8.Malware.Gen

How to remove Razy.580153?

Razy.580153 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment