Malware

Razy.679690 removal

Malware Removal

The Razy.679690 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.679690 virus can do?

  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Attempts to modify UAC prompt behavior

How to determine Razy.679690?


File Info:

crc32: FD537D52
md5: 5359d52c7d27d677201822258a15d5fc
name: 5359D52C7D27D677201822258A15D5FC.mlw
sha1: 15865fbb6b09113c63278f2d756a907b4a6d91d1
sha256: 5cf2d509ccaf93a6f5da765f1acc66f3b056a5115ed838961ce80a78b2056258
sha512: cfdac39f37f21a354e2b1e559b1138f6a54a345a165c03d11928465ead9cbce1edcd9e5db53344bb90f552c3593d4bca43c06acfcf3b4cd480c3d40b541958d4
ssdeep: 49152:Zo1RcrPKK1vC+PGz0h/Mpzx1eg3mn4RmC8:Zy0AqGz0JMFLemmn4h
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

ProgramID:
ProductName:
FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
FileDescription:
Translation: 0x0409 0x04e4

Razy.679690 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.PWS.Growtopia.57
CynetMalicious (score: 99)
ALYacGen:Variant.Razy.679690
CylanceUnsafe
ZillyaTrojan.Growtopia.Win32.3206
SangforTrojan.Win32.Save.a
Cybereasonmalicious.c7d27d
CyrenW32/Growtopia.B.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/PSW.Growtopia.U
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan-GameThief.Win32.Worgtop.gen
BitDefenderGen:Variant.Razy.679690
MicroWorld-eScanGen:Variant.Razy.679690
Ad-AwareGen:Variant.Razy.679690
SophosML/PE-A
BitDefenderThetaGen:NN.ZexaF.34294.0nKfaelFjVni
McAfee-GW-EditionGenericRXQI-XR!D85426EF2BAD
FireEyeGeneric.mg.5359d52c7d27d677
EmsisoftGen:Variant.Razy.679690 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PSW.Worgtop.aa
AviraHEUR/AGEN.1145046
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.34953A8
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitTrojan.Razy.DA5F0A
GDataWin32.Trojan.GrowtopiaStealer.A
AhnLab-V3Trojan/Win.XR.R451151
McAfeeGenericRXQI-XR!D85426EF2BAD
MAXmalware (ai score=88)
VBA32TrojanPSW.Growtopia
MalwarebytesSpyware.PasswordStealer.Growtopia
YandexTrojan.PWS.Growtopia!3qJ4BQv/rzc
IkarusTrojan-PSW.Growtopia
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Growtopia.I!tr.pws
AVGWin32:PWSX-gen [Trj]

How to remove Razy.679690?

Razy.679690 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment