Malware

Razy.596177 information

Malware Removal

The Razy.596177 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.596177 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Likely virus infection of existing system binary
  • Creates a copy of itself

Related domains:

0.tcp.ngrok.io

How to determine Razy.596177?


File Info:

crc32: 8CB1674F
md5: 7fae9a368a911e86a7e7fb0ca0d30119
name: 7FAE9A368A911E86A7E7FB0CA0D30119.mlw
sha1: 0874a642db0811a6225f7a0f4804f14fa7636928
sha256: 3741cd153a6d0379430136021b3624509f9328c702111665c6f225aa22b5adf2
sha512: 67b5d7fdcbac8a8da039408e1160a3c378645f1f7e39f91046ace92ca4e9bfbe00b9d87ddebcbb9505feb90fe5f45cae62278b38b3d6e34f5e50bbd6d96fd037
ssdeep: 24576:46xrSrpDUyHLRv58/6u8Fp3XQwYakCDXgitVpyLESdMW:460DUsLRvS/6u8LXv7DX5Naa
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: dasdasd
Assembly Version: 1.0.0.0
InternalName: force.exe
FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
FileDescription: x422x435x43ax441x442x43ex432x44bx439 x434x43ex43ax443x43cx435x43dx442 (.txt)
OriginalFilename: force.exe

Razy.596177 also known as:

Elasticmalicious (high confidence)
ClamAVWin.Packed.Ursu-7334536-0
ALYacGen:Variant.Razy.596177
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 004e37a91 )
K7AntiVirusTrojan ( 004e37a91 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.ECH
APEXMalicious
AvastMSIL:BFBot-A [Cryp]
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.596177
NANO-AntivirusTrojan.Win32.MLW.dwyhve
MicroWorld-eScanGen:Variant.Razy.596177
Ad-AwareGen:Variant.Razy.596177
SophosML/PE-A + Troj/MSIL-QP
BitDefenderThetaGen:NN.ZemsilF.34088.en0@a0!k!zi
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.7fae9a368a911e86
EmsisoftGen:Variant.Razy.596177 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.MSIL.Gen2
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Razy.D918D1
GDataGen:Variant.Razy.596177
AhnLab-V3Trojan/Win32.RL_Generic.R286066
McAfeeGenericRXGA-OH!7FAE9A368A91
MAXmalware (ai score=89)
MalwarebytesTrojan.Crypt.MSIL
IkarusTrojan.MSIL.Injector
FortinetMSIL/StubRC.AVB!tr
AVGMSIL:BFBot-A [Cryp]
Qihoo-360HEUR/QVM03.0.503B.Malware.Gen

How to remove Razy.596177?

Razy.596177 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment