Malware

Should I remove “Razy.61736”?

Malware Removal

The Razy.61736 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.61736 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • A process attempted to delay the analysis task by a long amount of time.
  • Exhibits behavior characteristic of Nymaim malware
  • Checks the version of Bios, possibly for anti-virtualization
  • Zeus P2P (Banking Trojan)
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz
kedqcq.in
dvsdgqpaxv.net
lxhoeql.net
xcnivotoaqaj.pw
eftellntoqro.in
idize.pw
teabjqpqkldd.com
sdxhnjjqgf.in
wwtypzsyw.com
igstvmezyj.in
vozyvfnl.pw
nqicabbaz.in
uzhxwpv.net
ldxgdggzy.pw
xjxfyextx.com

How to determine Razy.61736?


File Info:

crc32: 60DB6AAD
md5: e7d7a59dce1276f3d32478d0ea85107c
name: E7D7A59DCE1276F3D32478D0EA85107C.mlw
sha1: 2346560c8e0866b88cf304edb389329cb830c144
sha256: 5b698b348a32e736ee28dd65655381b760569ef9aa3b6692f701b74d13fe2fc5
sha512: 175e00341980bd1f6ff7def6815310d17c6af573f72dcc66e8f7af4799170555b1bf836d47a3dd50b2b85d95ad8d4c213f5e47323ecc314d69a8e9d300652a6f
ssdeep: 12288:Yv/I75VuzQioH3pIZ5z87Z6cMXABOeIMwvO+L+upCo:xruzQioH5Ifz2vMXABOeSF+up
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 1999-2010 Igor Pavlov
InternalName: 7zFM
FileVersion: 9.20
CompanyName: Igor Pavlov
ProductName: 7-Zip
ProductVersion: 9.20
FileDescription: 7-Zip File Manager
OriginalFilename: 7zFM.exe
Translation: 0x0409 0x04b0

Razy.61736 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.61736
FireEyeGeneric.mg.e7d7a59dce1276f3
ALYacGen:Variant.Razy.61736
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 004f0fbd1 )
BitDefenderGen:Variant.Razy.61736
K7GWTrojan ( 004f0fbd1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.34804.Mu0@aO14@Wmi
SymantecML.Attribute.HighConfidence
BaiduWin32.Trojan.Kryptik.ahr
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Nymaim-5627
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Kryptik.fbvvnq
RisingDownloader.Nymaim!8.781 (C64:YzY0OuF7DtGOwBnu)
Ad-AwareGen:Variant.Razy.61736
TACHYONTrojan/W32.Waldek.629248.B
EmsisoftGen:Variant.Razy.61736 (B)
ComodoMalware@#2d93hnks4bq6v
F-SecureHeuristic.HEUR/AGEN.1122439
DrWebTrojan.Inject2.24708
ZillyaTrojan.AgentGen.Win32.54
TrendMicroHT_WALDEK_FF120030.UVPM
McAfee-GW-EditionBehavesLike.Win32.Dropper.jc
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.fjomi
AviraHEUR/AGEN.1122439
Antiy-AVLTrojan/Win32.SGeneric
MicrosoftTrojanDownloader:Win32/Silcon!rfn
ArcabitTrojan.Razy.DF128
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Razy.61736
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.Generic.C1468777
McAfeeTrojan-FIQL!E7D7A59DCE12
MAXmalware (ai score=80)
VBA32TScope.Malware-Cryptor.SB
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.EYVW
TrendMicro-HouseCallHT_WALDEK_FF120030.UVPM
TencentMalware.Win32.Gencirc.10bdcd7c
YandexTrojan.GenAsa!7O05lzjiB8U
IkarusTrojan.Win32.Crypt
eGambitUnsafe.AI_Score_57%
FortinetW32/Kryptik.EYDH!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.973

How to remove Razy.61736?

Razy.61736 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment