Malware

Should I remove “Razy.641759 (B)”?

Malware Removal

The Razy.641759 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.641759 (B) virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Razy.641759 (B)?


File Info:

crc32: F4CCFBEA
md5: 153d0c76c294d1a5f72f5c949f6f6ecd
name: free_vps.exe
sha1: ed155c7e5f0cecbe09dc4402cdf3ab0db033327e
sha256: bfe687b513d768a3df760cf77502804bb245e381c238223192a89b7dd56faccc
sha512: 479411dc5cf6e7013153a9cf95d54e4e1f54997a437a6733de656febaa42a72ac973d7b2acf194e5c1d154ff96497ae27869587eccd3f6e6b93a628d406d699b
ssdeep: 192:eg4/5czVueiortdrDKzW/jGZl2I2koyLet:eg4/Gzmo5drD0kjql2IN9e
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 Discord 2020
Assembly Version: 1.0.0.0
InternalName: StealerBin.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments: Discord
ProductName: Discord
ProductVersion: 1.0.0.0
FileDescription: Discord
OriginalFilename: StealerBin.exe

Razy.641759 (B) also known as:

MicroWorld-eScanGen:Variant.Razy.641759
FireEyeGen:Variant.Razy.641759
ALYacGen:Variant.Razy.641759
CylanceUnsafe
BitDefenderGen:Variant.Razy.641759
Cybereasonmalicious.e5f0ce
Invinceaheuristic
BitDefenderThetaGen:NN.ZemsilF.34110.am0@aGfhyDh
F-ProtW32/MSIL_Agent.BIL.gen!Eldorado
APEXMalicious
GDataGen:Variant.Razy.641759
KasperskyHEUR:Trojan-PSW.MSIL.Stealer.gen
AvastWin32:PWSX-gen [Trj]
Ad-AwareGen:Variant.Razy.641759
DrWebTrojan.PWS.DiscordNET.12
ZillyaTrojan.Discord.Win32.1234
McAfee-GW-EditionGenericRXKH-EM!153D0C76C294
EmsisoftGen:Variant.Razy.641759 (B)
IkarusTrojan.MSIL.PSW
CyrenW32/MSIL_Agent.BIL.gen!Eldorado
JiangminTrojan.PSW.MSIL.vpu
MAXmalware (ai score=88)
Antiy-AVLTrojan[PSW]/MSIL.Stealer
Endgamemalicious (high confidence)
ArcabitTrojan.Razy.D9CADF
ZoneAlarmHEUR:Trojan-PSW.MSIL.Stealer.gen
MicrosoftPWS:MSIL/Discord.GA!MTB
AhnLab-V3Trojan/Win32.Stealer.C4065582
McAfeeGenericRXKH-EM!153D0C76C294
VBA32TScope.Trojan.MSIL
MalwarebytesSpyware.PasswordStealer
ESET-NOD32a variant of MSIL/PSW.Discord.AT
RisingStealer.Discord!8.10A86 (TFE:dGZlOgxaoCObwpVWig)
FortinetMSIL/Discord.AT!tr
AVGWin32:PWSX-gen [Trj]
PandaTrj/GdSda.A

How to remove Razy.641759 (B)?

Razy.641759 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment