Malware

Should I remove “Razy.689923”?

Malware Removal

The Razy.689923 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.689923 virus can do?

  • Network activity detected but not expressed in API logs

How to determine Razy.689923?


File Info:

crc32: BFC02F2D
md5: 3d3247203e2d830bb743989df6d5d70b
name: winload.exe
sha1: 3adaf442089418fb4510d2f8e74c7136a503e9a2
sha256: 840a9d22afaf6d4ebdbc1fa4892ca75434628a3bc2724f1813589e1a00b6c86c
sha512: a65f45ea6211d8ad5d6c45ec4b759578bb03af18f585fc3f36fa075a2652a1fbb38c4e194769707756ffb1bcf93678c5217ecb5f560282a6d918c620763d5216
ssdeep: 6144:q1UFeJwf8YbXa4w8MHAiIsa9RjauOpCet7wEav5V:+wfvbK4w6jPO3tEEa
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: xa9 Microsoft Corpotation, 2020
Assembly Version: 10.0.18463.127
InternalName: winload.exe
FileVersion: 10.0.18463.127
CompanyName: xa9 Microsoft Corpotation, 2020
LegalTrademarks: xa9 Microsoft Corpotation, 2020
Comments: OS loader
ProductName: Loader OS windows
ProductVersion: 10.0.18463.127
FileDescription: WinLoad
OriginalFilename: winload.exe

Razy.689923 also known as:

MicroWorld-eScanGen:Variant.Razy.689923
Qihoo-360Generic/Trojan.PSW.c9f
McAfeeArtemis!3D3247203E2D
ALYacGen:Variant.Razy.689923
CylanceUnsafe
K7AntiVirusSpyware ( 005572ac1 )
BitDefenderGen:Variant.Razy.689923
K7GWSpyware ( 005572ac1 )
CrowdStrikewin/malicious_confidence_80% (W)
Invinceaheuristic
BitDefenderThetaGen:NN.ZemsilF.34132.nq0@aed5BVi
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTrojanSpy.Win32.COINS.USXVPG620
AvastWin32:Trojan-gen
GDataGen:Variant.Razy.689923
KasperskyHEUR:Trojan-PSW.MSIL.Stelega.gen
AlibabaTrojanPSW:MSIL/Stelega.4b406e84
APEXMalicious
TencentMsil.Trojan-qqpass.Qqrob.Lkxm
SophosMal/Generic-S
F-SecureTrojan.TR/Spy.Agent.kquct
TrendMicroTrojanSpy.Win32.COINS.USXVPG620
FireEyeGeneric.mg.3d3247203e2d830b
EmsisoftGen:Variant.Razy.689923 (B)
IkarusTrojan.MSIL.Spy
AviraTR/Spy.Agent.kquct
MAXmalware (ai score=80)
Antiy-AVLTrojan[PSW]/MSIL.Stelega
ArcabitTrojan.Razy.DA8703
ZoneAlarmHEUR:Trojan-PSW.MSIL.Stelega.gen
MicrosoftTrojan:MSIL/FormBook.CD!MTB
CynetMalicious (score: 85)
Ad-AwareGen:Variant.Razy.689923
MalwarebytesSpyware.Agent
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Spy.Agent.CEL
RisingSpyware.Agent!8.C6 (CLOUD)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetMSIL/Agent.CEL!tr.spy
AVGWin32:Trojan-gen
Cybereasonmalicious.208941
Paloaltogeneric.ml

How to remove Razy.689923?

Razy.689923 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment