Malware

Razy.639966 information

Malware Removal

The Razy.639966 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.639966 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Razy.639966?


File Info:

crc32: 4E2166D3
md5: 45265a892236a65be9cdce7ae5b60419
name: 98kksjh.exe
sha1: 6d31ff2d02067f44e3d32ab4f3358a35ddd3ac58
sha256: 99e619d50225a860298d04875a23481fa26cec511f58e09474783a1d6d2e5c3e
sha512: ba6708f73c2152483812b912a08b805efa4d91d72348369703b30f9e1b79c6427b986fa9f2de9fbfe90a7f1b19a65eecb8f7086ff6700bb4126dc6af82158a2a
ssdeep: 768:AoJXsBBrKdZirYzRVKPTPTyi2gFT9lh875apUa1wecCdrMltlDIvM8:NuBBrKbLzuPb+i2gh9Q75EAeRdraDIf
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: tekstom
FileVersion: 1.00
CompanyName: Gasher
ProductName: FICH
ProductVersion: 1.00
FileDescription: Dyksvmmer
OriginalFilename: tekstom.exe

Razy.639966 also known as:

MicroWorld-eScanGen:Variant.Razy.639966
McAfeeArtemis!45265A892236
CylanceUnsafe
AlibabaBackdoor:Win32/Remcos.0afeb987
K7GWTrojan ( 005644de1 )
CyrenW32/VBKrypt.AHN.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.ELLA
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Dropper.Razy-7661440-0
GDataGen:Variant.Razy.639966
KasperskyBackdoor.Win32.Remcos.omi
BitDefenderGen:Variant.Razy.639966
AvastFileRepMalware
TencentWin32.Trojan.Inject.Auto
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.BadFile.ct
EmsisoftGen:Variant.Razy.639966 (B)
F-ProtW32/VBKrypt.AHN.gen!Eldorado
ArcabitTrojan.Razy.D9C3DE
AegisLabTrojan.Win32.Remcos.m!c
ZoneAlarmBackdoor.Win32.Remcos.omi
MicrosoftTrojan:Win32/Wacatac.C!ml
ALYacGen:Variant.Razy.639966
MAXmalware (ai score=99)
Ad-AwareGen:Variant.Razy.639966
MalwarebytesTrojan.GuLoader.VB
TrendMicro-HouseCallTROJ_GEN.R002H0CDC20
RisingBackdoor.Remcos!8.B89E (CLOUD)
FortinetW32/GenKryptik.ELKW!tr
BitDefenderThetaGen:NN.ZevbaCO.34106.gm0@amVYidci
AVGFileRepMalware
PandaTrj/GdSda.A
Qihoo-360Generic/Trojan.4e3

How to remove Razy.639966?

Razy.639966 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment