Malware

About “Razy.661429” infection

Malware Removal

The Razy.661429 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.661429 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Sniffs keystrokes
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
freetexthost.com

How to determine Razy.661429?


File Info:

crc32: ECCCB4EF
md5: 5f28c2a1705f9a515aed6b2b6615ab7f
name: 5F28C2A1705F9A515AED6B2B6615AB7F.mlw
sha1: 6b9fb46f720992df8dbe4092b34518acf58683c9
sha256: 322c196faac6d8a3224a2140b953d0598d0f5b6162d2db3b27cb782ee44fce7f
sha512: 4e227e38c85cc2a0997ea115fc7b61e84a67f4a5f7c91c64d8ce25cc1a8c2fa6c8503b02c045c4c2ef608b6a750cbf9801b9b542a0f6d752e69bac3b85a78dea
ssdeep: 1536:5QIuVQny16krdl+fJ447cled9pHY/ljwBixPmAg2jVdF8f4T4GXHsyPljg9abZh:5QSny16awTcle7NyBw4xPmARjdC0Xsy
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2015
Assembly Version: 1.3.3.33
InternalName: zwxwin86.exe
FileVersion: 1.0.3.2
Comments: zwxwin86
ProductName: zwxwin86
ProductVersion: 1.0.3.2
FileDescription: zwxwin86
OriginalFilename: zwxwin86.exe

Razy.661429 also known as:

K7AntiVirusSpyware ( 004d9ca51 )
LionicTrojan.Win32.Blocker.j!c
DrWebTrojan.MulDrop6.23931
MicroWorld-eScanGen:Variant.Razy.661429
ALYacGen:Variant.Razy.661429
CylanceUnsafe
SangforTrojan.Win32.Save.a
AlibabaRansom:Win32/Blocker.967fa4b4
K7GWSpyware ( 004d9ca51 )
Cybereasonmalicious.1705f9
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Spy.Agent.AJX
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 99)
KasperskyTrojan-Ransom.Win32.Blocker.hzoq
BitDefenderGen:Variant.Razy.661429
NANO-AntivirusTrojan.Win32.Agent.dzkxzn
TencentWin32.Trojan.Blocker.Sxeu
Ad-AwareGen:Variant.Razy.661429
SophosMal/MSIL-AV
ComodoMalware@#91xli2ecf2bk
BitDefenderThetaGen:NN.ZemsilF.34142.fq0@aOaZxom
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.5f28c2a1705f9a51
EmsisoftGen:Variant.Razy.661429 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Blocker.avq
AviraTR/Spy.Gen
eGambitUnsafe.AI_Score_97%
Antiy-AVLTrojan/Generic.ASMalwS.163A0DA
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojanSpy:Win32/Skeeyah.A!rfn
ArcabitTrojan.Razy.DA17B5
ZoneAlarmTrojan-Ransom.Win32.Blocker.hzoq
GDataGen:Variant.Razy.661429
McAfeeArtemis!5F28C2A1705F
MAXmalware (ai score=100)
VBA32Hoax.Blocker
PandaTrj/GdSda.A
YandexTrojan.Blocker!wGViJtMDB2g
IkarusTrojan-Dropper.Win32.Dapato
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.AJX!tr.spy
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Razy.661429?

Razy.661429 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment