Malware

Razy.675349 removal guide

Malware Removal

The Razy.675349 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.675349 virus can do?

  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Attempts to modify UAC prompt behavior

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Razy.675349?


File Info:

crc32: 01F91165
md5: 565b0fe992ec4697cd485d3a013fddb8
name: 565B0FE992EC4697CD485D3A013FDDB8.mlw
sha1: 48a97b0264682af663221eccdf13d8d74276f181
sha256: 8def8f3c5921b4994649839a593ff37574901e13a6c57466664e266a56054f33
sha512: 021dea2d752b128c160187d1948a52c142b7cdca32ed0f2fffef0d21421fe9028ed2113086374930ea9c313fe598e7d617939ab725532520500e77d2b1bdceab
ssdeep: 12288:9lcveh4Ux2hD60zDCMeWEnBNfZWMSwoAfUABGuc4r7BmmFGKT1fEjhJL:Xx4UyBP/cPfQMS/uUAwu3FEUfc1
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

ProgramID:
ProductName:
FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
FileDescription:
Translation: 0x0409 0x04e4

Razy.675349 also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 99)
ALYacGen:Variant.Razy.675349
CylanceUnsafe
ZillyaTrojan.Worgtop.Win32.25
SangforTrojan.Win32.Save.a
Cybereasonmalicious.992ec4
CyrenW32/Growtopia.B.gen!Eldorado
ESET-NOD32a variant of Win32/PSW.Growtopia.U
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan-GameThief.Win32.Worgtop.gen
BitDefenderGen:Variant.Razy.675349
MicroWorld-eScanGen:Variant.Razy.675349
Ad-AwareGen:Variant.Razy.675349
BitDefenderThetaGen:NN.ZexaF.34170.1mKfa8ZiBZki
McAfee-GW-EditionBehavesLike.Win32.PUPXAN.cc
FireEyeGeneric.mg.565b0fe992ec4697
EmsisoftGen:Variant.Razy.675349 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.PSW.Worgtop.aa
AviraHEUR/AGEN.1135125
eGambitUnsafe.AI_Score_76%
Antiy-AVLTrojan/Generic.ASMalwS.3483744
MicrosoftTrojan:Script/Phonzy.B!ml
GDataWin32.Trojan.GrowtopiaStealer.A
McAfeeArtemis!565B0FE992EC
MAXmalware (ai score=82)
VBA32Trojan.Wacatac
MalwarebytesSpyware.PasswordStealer.Growtopia
YandexTrojan.PWS.Growtopia!4jWmwFBckvg
IkarusTrojan-PSW.Growtopia
FortinetW32/Growtopia.I!tr.pws
AVGWin32:PWSX-gen [Trj]

How to remove Razy.675349?

Razy.675349 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment