Malware

Razy.906856 removal instruction

Malware Removal

The Razy.906856 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.906856 virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Razy.906856?


File Info:

crc32: 72EB475D
md5: bd1a9cfdd264795006a2ef1552601488
name: BD1A9CFDD264795006A2EF1552601488.mlw
sha1: 8a634a8b8296e49c6f1dd7cef89a8701bfcb147a
sha256: 0979bb450e1548f613090a75932206e40cc84975d52c3720619422ec01bc55a1
sha512: a6cee58ab7447be96238ef428edbb231cdc1403fb02d9586250586edc5ef7bde86ea4e01a80ee2b5214cfaa47ac40ac78327f558e902314081bfeb509bda288e
ssdeep: 48:aF2k+IYYTAxB5EC7BWnVxAiidlxav2trgtQvh2v:cCMAOED7a6c22
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Razy.906856 also known as:

K7AntiVirusPassword-Stealer ( 0049b09a1 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen6.57235
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacGen:Variant.Razy.906856
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWPassword-Stealer ( 0049b09a1 )
Cybereasonmalicious.dd2647
BaiduWin32.Trojan-PSW.Agent.l
CyrenW32/Trojan.EOKO-3815
ESET-NOD32Win32/PSW.Agent.NYQ
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.CosmicDuke-6376318-0
KasperskyHEUR:Backdoor.Win32.CosmicDuke.gen
BitDefenderGen:Variant.Razy.906856
NANO-AntivirusTrojan.Win32.CosmicDuke.dbzksi
ViRobotTrojan.Win32.CosmicDuke.1314325
MicroWorld-eScanGen:Variant.Razy.906856
TencentMalware.Win32.Gencirc.10b3d341
Ad-AwareGen:Variant.Razy.906856
SophosML/PE-A + Troj/CosDuke-C
ComodoTrojWare.Win32.CosmicDuke.DB@6lnk05
F-SecureTrojan:W32/CosmicDuke.C
BitDefenderThetaGen:NN.ZexaF.34236.VmZ@a8mOibhi
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_SKEEYAH_FC170192.UVPA
McAfee-GW-EditionPWS-FBWV!BD1A9CFDD264
FireEyeGeneric.mg.bd1a9cfdd2647950
EmsisoftGen:Variant.Razy.906856 (B)
JiangminBackdoor/CosmicDuke.i
AviraTR/Rogue.11473269
Antiy-AVLTrojan[Backdoor]/Win32.AGeneric
MicrosoftTrojanDownloader:Win32/Upatre
ArcabitTrojan.Razy.DDD668
SUPERAntiSpywarePUP.CosmicDuke/Variant
ZoneAlarmHEUR:Backdoor.Win32.CosmicDuke.gen
GDataGen:Variant.Razy.906856
AhnLab-V3Trojan/Win32.Agent.R131885
Acronissuspicious
McAfeePWS-FBWV!BD1A9CFDD264
MAXmalware (ai score=100)
VBA32BScope.Backdoor.CosmicDuke
MalwarebytesBackdoor.CosmicDuke
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_SKEEYAH_FC170192.UVPA
RisingBackdoor.Win32.CosmicDuke.b (CLASSIC)
YandexTrojan.GenAsa!Xxdu1b+ysKo
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7204681.susgen
FortinetW32/Agent.NYQ.PWS!tr
AVGWin32:Malware-gen

How to remove Razy.906856?

Razy.906856 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment