Malware

Razy.588241 removal guide

Malware Removal

The Razy.588241 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.588241 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Steals private information from local Internet browsers
  • Anomalous binary characteristics

Related domains:

www.ipcode.pw
iplogger.org
apps.identrust.com
isrg.trustid.ocsp.identrust.com
crl.identrust.com
ocsp.int-x3.letsencrypt.org
www.infokscents.com

How to determine Razy.588241?


File Info:

crc32: 85FF99A0
md5: 482ba54a1ddc12153867214ed0d24903
name: tmpmoj6itp2
sha1: c61b305ae63a764fc8e4678bd5fe580afc53233a
sha256: 73eb384c6c3730fdd2e2fc56104a08dc6b6cf07bf89b0f971097b7325a230b78
sha512: a8ccfaa76793bfb3a114c956b092ab203680781f4128ec96b05368ca40fabfd8ce77330485c5279cb35629e2d0bb293ad8c9706c2a8069c8772e5f775cdd7631
ssdeep: 12288:+yIF64IJMp/kKwRvZ/15zpDKaJ7FSzF4unZvwE4EOJLpaDREE0WmMVxaxk3ae1Sf:+yI44Ia6KMbKsRSznAa2E07MVxdJ1Sf
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion:
CompanyName:
Comments: This installation was built with Inno Setup.
ProductName: searzar
ProductVersion: 20.06
FileDescription: searzar Setup
Translation: 0x0000 0x04b0

Razy.588241 also known as:

MicroWorld-eScanGen:Variant.Razy.588241
McAfeeRDN/Generic PWS.y
CylanceUnsafe
AegisLabTrojan.Win32.Disbuk.i!c
SangforMalware
K7AntiVirusSpyware ( 005484541 )
BitDefenderGen:Variant.Razy.588241
K7GWSpyware ( 005484541 )
CrowdStrikewin/malicious_confidence_80% (D)
TrendMicroTROJ_GEN.R035C0PFQ20
SymantecTrojan.Gen.2
APEXMalicious
AvastWin32:PWSX-gen [Trj]
GDataGen:Variant.Razy.588241
KasperskyHEUR:Trojan-PSW.Win32.Disbuk.gen
AlibabaTrojanSpy:Win32/Socelars.c6aa91d3
RisingStealer.Socelars!1.BC83 (TFE:5:qfZCvmqwmCC)
SophosMal/Generic-S
ComodoMalware@#1dib7iba8y0qy
F-SecureHeuristic.HEUR/AGEN.1120937
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
FireEyeGen:Variant.Razy.588241
EmsisoftGen:Variant.Razy.588241 (B)
IkarusTrojan-Spy.Agent
CyrenW32/Trojan.HPLE-9113
WebrootW32.Trojan.Gen
Aviraappvideo.exe
Antiy-AVLTrojan[PSW]/Win32.Disbuk
Endgamemalicious (high confidence)
ArcabitTrojan.Razy.D8F9D1
ZoneAlarmHEUR:Trojan-PSW.Win32.Disbuk.gen
MicrosoftPUA:Win32/Vigua.A
AhnLab-V3Malware/Win32.RL_Generic.R339916
MAXmalware (ai score=100)
MalwarebytesSpyware.PasswordStealer
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Spy.Socelars.S
TrendMicro-HouseCallTROJ_GEN.R035C0PFQ20
TencentWin32.Trojan-qqpass.Qqrob.Pbpj
FortinetW32/Socelars.S!tr
BitDefenderThetaGen:NN.ZexaF.34130.FmLfa4ylaGnj
AVGWin32:PWSX-gen [Trj]
Cybereasonmalicious.a1ddc1
Qihoo-360Win32/Trojan.PSW.3d5

How to remove Razy.588241?

Razy.588241 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment