Malware

Should I remove “Razy.727359”?

Malware Removal

The Razy.727359 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.727359 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Razy.727359?


File Info:

crc32: 56BE5ACE
md5: f51a41f40d565d00214d9601d4cbf1d0
name: F51A41F40D565D00214D9601D4CBF1D0.mlw
sha1: 4d1d76f8b6049a67befa98d79676eef0abd9e305
sha256: d25b3531eb841213ebe9bad92e8d6c9184e2b1b6d6b38a8c54f9dd0335164030
sha512: fdbcb60fada55dc6750e505af7cdc32520f28b489ae63cd3c4664b663f51e64532db3dc1286f9d264189393883e6285cec67bd94bd55bb75d50ccce3f67244df
ssdeep: 768:WBpD2he3LNMSX+H+TtlSdw8cMn4HjyC2NWWyAPhTHkTK4pUPQ0dIVYPcda3:8pD22H/TdMo8PZPhzkPBKmYEda3
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: firstG.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: firstG.exe

Razy.727359 also known as:

K7AntiVirusTrojan ( 0055e39a1 )
Elasticmalicious (high confidence)
DrWebTrojan.KillProc.28702
CynetMalicious (score: 99)
ALYacGen:Variant.Razy.727359
CylanceUnsafe
ZillyaTrojan.Injector.Win32.397529
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaRansom:Win32/Blocker.8e07ae4c
K7GWTrojan ( 0055e39a1 )
Cybereasonmalicious.40d565
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.CCF
APEXMalicious
AvastMSIL:Crypt-RO [Trj]
KasperskyTrojan-Ransom.Win32.Blocker.cksf
BitDefenderGen:Variant.Razy.727359
NANO-AntivirusTrojan.Win32.Blocker.chsacn
MicroWorld-eScanGen:Variant.Razy.727359
TencentWin32.Trojan.Blocker.Eams
Ad-AwareGen:Variant.Razy.727359
SophosMal/Generic-S
ComodoMalware@#dj2mxfnye1zl
BitDefenderThetaGen:NN.ZemsilF.34142.em0@a8mUZkb
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_SPNR.38JE13
McAfee-GW-EditionBehavesLike.Win32.Generic.kh
FireEyeGeneric.mg.f51a41f40d565d00
EmsisoftGen:Variant.Razy.727359 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1124825
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.4E0058
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Malagent
ArcabitTrojan.Razy.DB193F
ZoneAlarmTrojan-Ransom.Win32.Blocker.cksf
GDataGen:Variant.Razy.727359
McAfeeArtemis!F51A41F40D56
MAXmalware (ai score=100)
VBA32Hoax.Blocker
PandaGeneric Malware
TrendMicro-HouseCallTROJ_SPNR.38JE13
IkarusPUA.InstallCore
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Blocker.CKSF!tr
AVGMSIL:Crypt-RO [Trj]
Paloaltogeneric.ml

How to remove Razy.727359?

Razy.727359 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment