Malware

About “Razy.679792 (B)” infection

Malware Removal

The Razy.679792 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.679792 (B) virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Razy.679792 (B)?


File Info:

crc32: 96EC9809
md5: 0c9383d8f8dd367a91e09c5b91b44072
name: 0C9383D8F8DD367A91E09C5B91B44072.mlw
sha1: 7bc0b36366eacae916ff1e4a5d8bf820bf7a93bf
sha256: 24ae858e20dea57c481159b4d36d20c75eef6ad6271a57fb4a379b32714db8b0
sha512: ab9a0f918561ed8b950a747479255811628f0285f089bd7b160ee656e390fae95a64f2455b7a8619f8c40256a51d46bd6f51cd86564495b042bb03cb3b4dd0a0
ssdeep: 1536:kKqDIJRU4lhxZs0xZ298Lxicj2SCmGpT:kKqk3DTno8L0HrT
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: Application Frame Host
FileVersion: 10.0.19041.746 (WinBuild.160101.0800)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 10.0.19041.746
FileDescription: Application Frame Host
OriginalFilename: ApplicationFrameHost.exe
Translation: 0x0409 0x04b0

Razy.679792 (B) also known as:

Elasticmalicious (high confidence)
ALYacGen:Variant.Razy.679792
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.Razy.679792
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/ClipBanker.MZ
APEXMalicious
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.MSIL.Generic
MicroWorld-eScanGen:Variant.Razy.679792
Ad-AwareGen:Variant.Razy.679792
SophosGeneric ML PUA (PUA)
BitDefenderThetaGen:NN.ZemsilF.34126.dm0@a0hnnzdi
FireEyeGeneric.mg.0c9383d8f8dd367a
EmsisoftGen:Variant.Razy.679792 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitTrojan.Razy.DA5F70
GDataGen:Variant.Razy.679792
MAXmalware (ai score=83)
IkarusTrojan.MSIL.Injector
MaxSecureTrojan.Malware.300983.susgen

How to remove Razy.679792 (B)?

Razy.679792 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment