Malware

About “Razy.596401” infection

Malware Removal

The Razy.596401 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.596401 virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

How to determine Razy.596401?


File Info:

crc32: F704F070
md5: ffad4ab6f21c618220497a40e9093896
name: FFAD4AB6F21C618220497A40E9093896.mlw
sha1: 9206c2e7fd38a0d7308dea5fdeb1fa18c3d8ba66
sha256: bfd3536a4d9c5ade220ed2cfec469f9d0738c8cabdab4fd05b5ce419facd1be2
sha512: 2de366272ee9e1270363edec3006ef8a100ebaec20178cb2d0925c3ce390277e5a519f4d864246874a7e093256ecf81e40ccf114f20bb998bde229827c6be636
ssdeep: 3072:ChOmTsF93UYfwC6GIoutAep8KnTMPg3YtjQ1HpQNYNzWq+qCq+qXunk1V4Ei6KX:Ccm4FmowdHoSRt5BC6i
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed, PECompact2 compressed

Version Info:

0: [No Data]

Razy.596401 also known as:

BkavW32.FamVT.DinwoodAATTC.Worm
K7AntiVirusRiskware ( 0040eff71 )
DrWebTrojan.Inject1.58305
MicroWorld-eScanGen:Variant.Razy.596401
McAfeeDropper-FVF!FFAD4AB6F21C
CylanceUnsafe
ZillyaDropper.DinwodGen.Win32.1
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDropper:Win32/Dinwod.553fed9a
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.6f21c6
TrendMicroTrojanSpy.Win32.BANKER.SMJC
BaiduWin32.Trojan.Agent.acb
CyrenW32/Trojan.HJVI-2850
ESET-NOD32a variant of Win32/Packed.BlackMoon.A potentially unwanted
APEXMalicious
TotalDefenseWin32/Oflwr.A!crypt
AvastWin32:Banker-NBH [Trj]
ClamAVWin.Trojan.Agent-1388676
GDataGen:Variant.Razy.596401
KasperskyTrojan-Dropper.Win32.Dinwod.acqn
BitDefenderGen:Variant.Razy.596401
NANO-AntivirusTrojan.Win32.Dinwod.ejafor
ViRobotTrojan.Win32.Agent.69310
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
TencentTrojan.Win32.GameteaSpy.a
Ad-AwareGen:Variant.Razy.596401
SophosTroj/Eydrop-A
ComodoPacked.Win32.MUPX.Gen@24tbus
F-SecureTrojan.TR/Crypt.ULPM.Gen
BitDefenderThetaGen:NN.ZexaF.34110.mmJfa017ibi
VIPRETrojan.Win32.Agent.xfc (v)
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Dropper.dm
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.ffad4ab6f21c6182
EmsisoftGen:Variant.Razy.596401 (B)
SentinelOneDFI – Malicious PE
F-ProtW32/Trojan2.QAPL
Endgamemalicious (high confidence)
WebrootW32.Trojan.Agent.Gen
AviraTR/Crypt.ULPM.Gen
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan[Dropper]/Win32.Dinwod
MicrosoftTrojanDropper:Win32/Dinwod
JiangminTrojanDropper.Dinwod.ale
ArcabitTrojan.Razy.D919B1
AegisLabTrojan.Win32.Dinwod.mxkF
ZoneAlarmTrojan-Dropper.Win32.Dinwod.acqn
AhnLab-V3Dropper/Win32.Dinwod.C3090206
Acronissuspicious
VBA32TrojanDropper.Dinwod
MAXmalware (ai score=84)
MalwarebytesTrojan.Dropper
TrendMicro-HouseCallTrojanSpy.Win32.BANKER.SMJC
RisingTrojan.Agent!1.AB1D (CLOUD)
YandexTrojan.DR.Dinwod!uVRTdtgm1dY
IkarusTrojan-Dropper.Win32.Dinwod
MaxSecureDropper.Dinwod.unm
FortinetW32/Agent.7136!tr
AVGWin32:Banker-NBH [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Dropper.852

How to remove Razy.596401?

Razy.596401 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment