Malware

What is “Razy.699581”?

Malware Removal

The Razy.699581 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.699581 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Steals private information from local Internet browsers
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
www.ipcode.pw
a.tomx.xyz
iplogger.org
apps.identrust.com
isrg.trustid.ocsp.identrust.com
crl.identrust.com
ocsp.int-x3.letsencrypt.org
www.asdgain.xyz

How to determine Razy.699581?


File Info:

crc32: C836CE31
md5: 148eb56c204b9b9e1843472e51c909d8
name: tmpzju7zauv
sha1: 6f120723ebaa3af03fce8e59d7439f29e1489b55
sha256: 45bfb2f9a906eea42cb46ceade7a4225b8ea64e007da77bf9d5c64d26483564b
sha512: 51985d7df45fd0b37bd4e2a6a797bcfc861f770e97046857cd5b5ab5c143c60c14193c2506a8ce75996ce87a85853e9dedf31ecc1928dbf6a849a4d21b56e575
ssdeep: 24576:+yIsS2rKZlgXuAyehDU1/u68XIMveE07MVxdD1u:+yIdUOKXP2PMVxdDA
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion:
CompanyName:
Comments: This installation was built with Inno Setup.
ProductName: searzar
ProductVersion: 20.06
FileDescription: searzar Setup
Translation: 0x0000 0x04b0

Razy.699581 also known as:

MicroWorld-eScanGen:Variant.Razy.699581
FireEyeGen:Variant.Razy.699581
CylanceUnsafe
K7AntiVirusSpyware ( 005484541 )
BitDefenderGen:Variant.Razy.699581
K7GWSpyware ( 005484541 )
CrowdStrikewin/malicious_confidence_80% (D)
BitDefenderThetaGen:NN.ZexaF.34130.FmLfaCsIIsgj
SymantecTrojan.Gen.2
KasperskyHEUR:Trojan-PSW.Win32.Disbuk.gen
AlibabaTrojanSpy:Win32/Socelars.229feb4b
AegisLabTrojan.Win32.Disbuk.i!c
RisingStealer.Socelars!1.BC83 (CLOUD)
SophosMal/Generic-S
ComodoMalware@#gdyptjn33lzz
F-SecureTrojan.TR/AD.DisSteal.cqc
McAfee-GW-EditionBehavesLike.Win32.AdwareFileTour.bc
EmsisoftGen:Variant.Razy.699581 (B)
IkarusTrojan-Spy.Agent
CyrenW32/Ransom.AYWE-5242
WebrootW32.Trojan.Gen
AviraTR/AD.DisSteal.cqc
FortinetW32/Disbuk.S!tr.pws
Endgamemalicious (high confidence)
ArcabitTrojan.Razy.DAACBD
ZoneAlarmHEUR:Trojan-PSW.Win32.Disbuk.gen
MicrosoftTrojan:Win32/Ymacco.AA2A
AhnLab-V3Malware/Win32.RL_Generic.R339916
McAfeeArtemis!148EB56C204B
MAXmalware (ai score=80)
VBA32TrojanPSW.Disbuk
MalwarebytesSpyware.PasswordStealer
APEXMalicious
ESET-NOD32a variant of Win32/Spy.Socelars.S
TencentWin32.Trojan-qqpass.Qqrob.Dxni
GDataGen:Variant.Razy.699581
AVGWin32:PWSX-gen [Trj]
Cybereasonmalicious.c204b9
AvastWin32:PWSX-gen [Trj]
Qihoo-360Win32/Trojan.PSW.3d5

How to remove Razy.699581?

Razy.699581 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment