Malware

How to remove “Razy.603962”?

Malware Removal

The Razy.603962 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.603962 virus can do?

  • Expresses interest in specific running processes
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Network activity detected but not expressed in API logs

How to determine Razy.603962?


File Info:

crc32: A3B2D840
md5: 049850bc2a2a6bcd397c637ca2bfc135
name: 049850BC2A2A6BCD397C637CA2BFC135.mlw
sha1: ce07354bac0d636853c655286eda5b4418fdb828
sha256: 7a0b7b22ac118cab9993c83180256541e4566b13f26493819f76b1cad729a7af
sha512: 04874485a17e2ba45469e7d89d72a443dd3edbbdf58f0eec7093454a14d2e0964b43ee35539ce7c7d913c767ab60c958fb4de929465bc69fb0fc70d0853b66ed
ssdeep: 98304:WpA1LeSYZ6OJWBhVGyHh7hD4TlRWFe1g:WEeFZ6OoBf+oe
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2020
InternalName: down
FileVersion: 6.3.0.11502
ProductName: down
BuildNumber: 9-359116784
ProductVersion: 6.3.0.11502
FileDescription: down
OriginalFilename: down
Translation: 0x0409 0x04b0

Razy.603962 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusAdware ( 0055be711 )
Elasticmalicious (high confidence)
DrWebTrojan.StartPage1.59294
CAT-QuickHealTrojan.GenericRI.S23532579
ALYacGen:Variant.Razy.603962
CylanceUnsafe
ZillyaTrojan.Agent.Win32.1353425
SangforTrojan.Win32.Save.a
BitDefenderGen:Variant.Razy.603962
K7GWAdware ( 0055be711 )
Cybereasonmalicious.c2a2a6
CyrenW32/Sality.AZ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.Agent.NUF
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:Trojan.Win32.Agent
NANO-AntivirusTrojan.Win32.StartPage1.hnzlvj
MicroWorld-eScanGen:Variant.Razy.603962
Ad-AwareGen:Variant.Razy.603962
SophosGeneric PUA MO (PUA)
BitDefenderThetaGen:NN.ZexaF.34266.@t0@aqWk4Wdj
TrendMicroTROJ_GEN.R03BC0GK321
McAfee-GW-EditionBehavesLike.Win32.Dropper.rh
FireEyeGeneric.mg.049850bc2a2a6bcd
EmsisoftGen:Variant.Razy.603962 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Agent.doxk
AviraADWARE/Agent.yogyv
Antiy-AVLTrojan/Generic.ASMalwS.30B570E
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Razy.603962
AhnLab-V3PUP/Win32.DownloadManager.C4112084
McAfeeGenericRXAA-AA!049850BC2A2A
MAXmalware (ai score=82)
VBA32BScope.Trojan.StartPage
RisingTrojan.Generic@ML.82 (RDML:5CwEAWTytMtyGc6lJHbi3g)
FortinetAdware/Agent
PandaTrj/GdSda.A

How to remove Razy.603962?

Razy.603962 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment