Malware

Razy.659980 information

Malware Removal

The Razy.659980 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.659980 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Looks up the external IP address

Related domains:

z.whorecord.xyz
a.tomx.xyz
checkip.dyndns.org

How to determine Razy.659980?


File Info:

crc32: 1A3EA8CE
md5: ed9c9e70484b556c80e7f8bc1cd1787b
name: ED9C9E70484B556C80E7F8BC1CD1787B.mlw
sha1: 4f06d74ce7c1d9d30f8116a5c5d39cee92ba9256
sha256: 215ebc7a155186b87ccfb40b8b4c1b0999f128ce1ebdcaa696640684dea2fb1a
sha512: c80d763d53e43709c60fda4e1c56a28bbecfe8972bf41bda02a628726df6e188a77d2bd873b22cd2caa67d729ba5b1f52f021b3bcc9b3640f0f8d9c1870473ca
ssdeep: 24576:sB0DXJsHB0DH+lq8jhvibgGFlAuLhdUHcKT6G2f+2K0rjHn/VMJ4LJERfvZHwc2:xXJpH+lq8jhvibgGFlAuLhdUHcKT6G2
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2017
Assembly Version: 1.0.0.0
InternalName: Md5 Crusher.exe
FileVersion: 1.0.0.0
ProductName: Md5 Crusher
ProductVersion: 1.0.0.0
FileDescription: Md5 Crusher
OriginalFilename: Md5 Crusher.exe

Razy.659980 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.DnsChange.8239
ALYacGen:Variant.Razy.659980
SangforTrojan.Win32.Generic.8
CrowdStrikewin/malicious_confidence_80% (D)
Cybereasonmalicious.0484b5
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.659980
NANO-AntivirusTrojan.Win32.DnsChange.ewxslr
MicroWorld-eScanGen:Variant.Razy.659980
TencentWin32.Trojan.Generic.Anps
Ad-AwareGen:Variant.Razy.659980
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34294.cr0@a0JH2fk
McAfee-GW-EditionPWS-FCZZ!ED9C9E70484B
FireEyeGen:Variant.Razy.659980
EmsisoftGen:Variant.Razy.659980 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Generic.bwrps
eGambitUnsafe.AI_Score_96%
Antiy-AVLTrojan/Generic.ASMalwS.23E3648
MicrosoftBackdoor:Win32/Bladabindi!ml
ArcabitTrojan.Razy.DA120C
GDataGen:Variant.Razy.659980
McAfeePWS-FCZZ!ED9C9E70484B
MAXmalware (ai score=84)
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic!tr
AVGWin32:Malware-gen

How to remove Razy.659980?

Razy.659980 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment