Malware

Razy.594772 information

Malware Removal

The Razy.594772 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.594772 virus can do?

  • Network anomalies occured during the analysis.
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Queries information on disks, possibly for anti-virtualization
  • Deletes its original binary from disk
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Generates some ICMP traffic
  • Created a service that was not started
  • Uses suspicious command line tools or Windows utilities

Related domains:

www.slsbzutupz.com
api.ip.sb
ip-api.com

How to determine Razy.594772?


File Info:

crc32: CD93F896
md5: 3e8d3576a28ee7e6eeee4cc8b34b7dab
name: netsys.exe
sha1: 27d5d5154904c57e5820a26731f5ea315a1cda47
sha256: 14a78fdce5d03784f62398e3f822908c9205b9869c5101bac568ee1116484de0
sha512: 4e9a280ac54f3f59d699de0c0f3432f2df07693395733810ca89a5b0e8554c6eb08c080c07aadba445212bfb084f7039a365cd6f33b4f1f262c590c9c6030880
ssdeep: 24576:jWlPcN8B8C3J9U8FJRRJLkrbOywfwx6WL0zd5W:kErC3XvRRJLkOfwx70zd5W
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Razy.594772 also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanGen:Variant.Razy.594772
FireEyeGeneric.mg.3e8d3576a28ee7e6
McAfeeArtemis!3E8D3576A28E
K7AntiVirusTrojan ( 0046f3e51 )
BitDefenderGen:Variant.Razy.594772
K7GWTrojan ( 0046f3e51 )
Cybereasonmalicious.54904c
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
GDataGen:Variant.Razy.594772
KasperskyHEUR:Trojan.Win32.Staser.vho
AlibabaTrojan:Win32/Staser.f9cfbc84
AegisLabTrojan.Win32.Staser.4!c
RisingTrojan.Agent!8.B1E (CLOUD)
Ad-AwareGen:Variant.Razy.594772
EmsisoftGen:Variant.Razy.594772 (B)
F-SecureHeuristic.HEUR/AGEN.1046664
McAfee-GW-EditionBehavesLike.Win32.Dropper.dh
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.Agent
JiangminTrojan.Staser.bxs
AviraHEUR/AGEN.1046664
Endgamemalicious (high confidence)
ArcabitTrojan.Razy.D91354
ZoneAlarmHEUR:Trojan.Win32.Staser.vho
MicrosoftTrojan:Win32/Occamy.C
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34090.8uW@aSgY1@li
ALYacGen:Variant.Razy.594772
MAXmalware (ai score=87)
CylanceUnsafe
ESET-NOD32a variant of Win32/Agent.UAF
TencentWin32.Trojan.Staser.Lnez
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/AGENT.UAF!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Trojan.5a3

How to remove Razy.594772?

Razy.594772 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment