Malware

How to remove “Razy.941556”?

Malware Removal

The Razy.941556 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.941556 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Polish
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
edgedl.me.gvt1.com

How to determine Razy.941556?


File Info:

crc32: EBE89C5D
md5: 60d7b1bba6983257835397e4f978cb98
name: 60D7B1BBA6983257835397E4F978CB98.mlw
sha1: 2d4e1b48b887def123e232ddb6382ad210b9cf94
sha256: 137a5389ff9078053fd119f0d45d25d25dbec4bf22cb8af943044c18804ba4b3
sha512: 74fa2d8264746e10b46180cbd1693fb5f7ac1fa663f8d41e6d5bdbb321905a4755ec767fe4d0166ffe3cc0a6e22e00caf9a8992429b3eebe6225ff2b01c0e8d6
ssdeep: 6144:H0iHZMRnpbyZPm1QqHf+wvQzzzTdvMs4q9:H0iHZMRnpbX1tl4zzzTRt
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x1209 0x04b8

Razy.941556 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
Cybereasonmalicious.417471
ESET-NOD32a variant of Win32/Kryptik.HMOY
APEXMalicious
AvastFileRepMalware
KasperskyUDS:Trojan.Win32.Mucc
BitDefenderGen:Variant.Razy.941556
MicroWorld-eScanGen:Variant.Razy.941556
Ad-AwareGen:Variant.Razy.941556
SophosML/PE-A
BitDefenderThetaGen:NN.ZevbaF.34170.hm0@aatb0uej
McAfee-GW-EditionBehavesLike.Win32.Fareit.ch
FireEyeGeneric.mg.517a12b2eb17c1c0
EmsisoftGen:Variant.Razy.941556 (B)
SentinelOneStatic AI – Malicious PE
MicrosoftTrojan:Win32/VBObfuse.SM!MTB
GDataGen:Variant.Razy.941556
AhnLab-V3Win-Trojan/VBKrand.Gen
McAfeeArtemis!517A12B2EB17
MAXmalware (ai score=82)
AVGFileRepMalware

How to remove Razy.941556?

Razy.941556 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment