Malware

Razy.694716 removal instruction

Malware Removal

The Razy.694716 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.694716 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup

How to determine Razy.694716?


File Info:

crc32: 84874B36
md5: a0584791437090f0da860c4c6702529b
name: A0584791437090F0DA860C4C6702529B.mlw
sha1: 47a50227baca8a7eaecc989f207379b65bbb135d
sha256: 615c5ec2cf428aaeef3fa1c7a574d51cd1ea0da3840b7542364b274beb298b94
sha512: c886015d85888d950c82d247bc520e6f281fd581fd566a4c367270f44200a12f053da0d26f69f59f0825d92b3282b6ccbaea4eedbf5fe62811b3c1ef67c82dc1
ssdeep: 12288:e4l3/rNCmRKJIf5BlAZ39kWRCLL2Ihq/qake7M1tJ0LFXQy:3l3zcmMJ85vANmPLNlO7MlS
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Iowa xa9 Drape Jewel 1997-2008
InternalName: Grace Yet Tub
FileVersion: 9.5
CompanyName: market maker Software AG
Comments: Leaf Bundy Gruff
ProductName: Jail Tlc Tried Burly Baud Weird
ProductVersion: 9.5
FileDescription: Prime Seeds Tie Root Lax Wags
OriginalFilename: Blood.exe
Translation: 0x0409 0x04b0

Razy.694716 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 002e9a531 )
Elasticmalicious (high confidence)
DrWebTrojan.Winlock.3285
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.694716
CylanceUnsafe
ZillyaTrojan.Pihun.Win32.30
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/ArchSMS.97b6f121
K7GWTrojan ( 002e9a531 )
Cybereasonmalicious.143709
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/LockScreen.AIV
APEXMalicious
TotalDefenseWin32/LockScreen.HY
AvastWin32:Malware-gen
KasperskyHEUR:Hoax.Win32.ArchSMS.gen
BitDefenderGen:Variant.Razy.694716
NANO-AntivirusRiskware.Win32.ArchSMS.ctvtfn
SUPERAntiSpywareTrojan.Agent/Gen-MalPE
MicroWorld-eScanGen:Variant.Razy.694716
TencentWin32.Trojan.Lockscreen.Ljjs
Ad-AwareGen:Variant.Razy.694716
SophosMal/Generic-S
VIPREHoax.Win32.ArchSMS (not malicious)
McAfee-GW-EditionBehavesLike.Win32.Rootkit.jc
FireEyeGeneric.mg.a0584791437090f0
EmsisoftGen:Variant.Razy.694716 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.ULPM.Gen2
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/LockScreen
ArcabitTrojan.Razy.DA99BC
AegisLabTrojan.Win32.Gimemo.lzpj
GDataGen:Variant.Razy.694716
TACHYONTrojan/W32.Agent.861184.BN
AhnLab-V3Trojan/Win32.Gimemo.R35378
McAfeeArtemis!A05847914370
MAXmalware (ai score=100)
VBA32BScope.Trojan-Ransom.Winlock.7312
MalwarebytesMalware.Heuristic.1003
PandaGeneric Malware
RisingRansom.LockScreen!8.83D (CLOUD)
IkarusTrojan.Win32.LockScreen
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Yakes.LS!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.ShimRAT.HgIASOYA

How to remove Razy.694716?

Razy.694716 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment