Malware

Razy.580317 information

Malware Removal

The Razy.580317 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.580317 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Russian
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Exhibits behavior characteristic of Nymaim malware
  • Zeus P2P (Banking Trojan)
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

ywdovsevgsix.pw
svngj.in
ucuhdnk.com
kppxbflesjf.net
foqgqdqsr.net
invzip.net
vbcgkn.net
wpudukhqmg.in
wcspy.in
jdpurrjkzkgk.com
fzblwv.pw
omfqa.net
dprksr.net
wcqiaalh.in
dvyezqaxh.com
uqwnuyawxf.pw
knveaqucq.in
gihbokthvssn.com
txpgmqumzysx.pw
yfnaaejlgige.com
ofsivu.in
ercpzkehlby.in
yfmyfhmbxi.pw
dfgqvlpyks.net
faqhruraowd.net
dkgzjthjpoj.in
vzprpo.in
odcpduelqe.com
vnxnmvtzivn.in
qermqzwkab.in
srbuyaqocfu.in
kazif.com
cmcgim.pw
uwyqoplqrdt.net
zsjcrtwdhxop.com
bflqmbg.net
efbhycwgyj.in
fkhksduzospm.pw
tpkjg.in
qqlmujyg.net
ydmiije.com
vhmxqpcai.in
midqldwxm.pw
newrile.com
pqquyngi.net
ynpbiofqlfgr.in
ynjbwaobfp.in
wgzfpldgrxf.net
siyoxdxq.pw
mreakfhszjcg.in

How to determine Razy.580317?


File Info:

crc32: 5F880F13
md5: 9df0d0b21d3ce6642a669fa50dc6c184
name: 9DF0D0B21D3CE6642A669FA50DC6C184.mlw
sha1: a60f1b7d8aa05f3618d545cdd13b213a8f5e6bf0
sha256: ddf9d0e2d15fbb5273e647960156da5ebf73e6407d85e17442206b2d16911ba2
sha512: 8da67dba453ae2a9aa83dff86eb9ba62c530cd05cb27ab37633fa1c5dc5916197ba6adefb0bd7dde370e9ff81e533da90478b3d68ae867bcbb32a3d71ad26852
ssdeep: 6144:FibC4066KDZHhFoSu75y9u92fkUATF5MDBPX8tszQSqBk0GxAJc:sC40fyZ4ZN92fk9CDV+SqBk0GxAJc
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Razy.580317 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.580317
FireEyeGeneric.mg.9df0d0b21d3ce664
McAfeeTrojan-FOLH!9DF0D0B21D3C
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan-Downloader ( 004d47d61 )
BitDefenderGen:Variant.Razy.580317
K7GWTrojan-Downloader ( 004d47d61 )
Cybereasonmalicious.21d3ce
BitDefenderThetaGen:NN.ZexaF.34804.YqW@aeG2aFok
CyrenW32/Nymaim.CJ.gen!Eldorado
SymantecPacked.Generic.546
ESET-NOD32Win32/TrojanDownloader.Nymaim.BA
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
RisingDownloader.Nymaim!8.781 (CLOUD)
Ad-AwareGen:Variant.Razy.580317
EmsisoftGen:Variant.Razy.580317 (B)
F-SecureHeuristic.HEUR/AGEN.1106768
McAfee-GW-EditionBehavesLike.Win32.Generic.ct
SophosMal/Generic-S
IkarusTrojan-Downloader.Win32.Nymaim
JiangminTrojan.Banker.GozNym.v
AviraHEUR/AGEN.1106768
MAXmalware (ai score=98)
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftTrojanDownloader:Win32/Nymaim.K
ArcabitTrojan.Razy.D8DADD
AhnLab-V3Trojan/Win32.GozNym.C2309320
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Razy.580317
CynetMalicious (score: 100)
Acronissuspicious
VBA32BScope.TrojanDownloader.Nymaim
ALYacGen:Variant.Razy.580317
MalwarebytesTrojan.Nymaim.Generic
PandaTrj/GdSda.A
TencentMalware.Win32.Gencirc.10ba83fd
YandexTrojan.PWS.GozNym!zuKU2QC1+ZA
SentinelOneStatic AI – Suspicious PE – Downloader
FortinetW32/Nymaim.BA!tr
WebrootW32.Trojan.Gen
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM20.1.E8C1.Malware.Gen

How to remove Razy.580317?

Razy.580317 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment