Malware

Razy.696787 removal guide

Malware Removal

The Razy.696787 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.696787 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Attempts to modify desktop wallpaper
  • Exhibits behavior characteristic of Cerber ransomware
  • Attempts to execute a binary from a dead or sinkholed URL
  • Writes a potential ransom message to disk
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Collects information to fingerprint the system

How to determine Razy.696787?


File Info:

crc32: B102DDF3
md5: 9aa50b1857be5611d91bcc5967db91d7
name: 9AA50B1857BE5611D91BCC5967DB91D7.mlw
sha1: 6fd06872996d72b73ab87e7f44aedec2d0139a85
sha256: b7a97e83ee61e287eca13aeb3b6317412b7169a435328661b6a75dae4a9db35c
sha512: 3065825d3f5f0bd148694bc254c2a5e458821a5f16417d76059b23ae60446debb3b470ef9848c36961dc043421a13fa7c77bdb212c322e408d25b6c4ac713a4e
ssdeep: 12288:teySOCn73uSYcAEDCNBcX2uEE8YLoeMhqrxIG:rSOC7uSnAEDJXgEt6Ct
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2012
InternalName: Java(TM) Web Start Launcher
FileVersion: 10.4.0.20
Full Version: 10.4.0.20
CompanyName: O racle Corporation
ProductName: Java(TM) Platform SE 7 U4
ProductVersion: 7.0.40.20
FileDescription: Java(TM) Web Start Launcher
OriginalFilename: javaws.exe
Translation: 0x0000 0x04b0

Razy.696787 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005224381 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.10589
CynetMalicious (score: 100)
CAT-QuickHealRansom.Cerber.A4
ALYacGen:Variant.Razy.696787
CylanceUnsafe
ZillyaTrojan.Agent.Win32.767373
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Cerber.ali1020013
K7GWTrojan ( 00508e331 )
Cybereasonmalicious.857be5
BaiduWin32.Trojan.Kryptik.alb
CyrenW32/Simda.BW.gen!Eldorado
ESET-NOD32a variant of Win32/Kryptik.FPVQ
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Ransomware.Cerber-9779171-1
KasperskyHEUR:Trojan-Ransom.Win32.Zerber.pef
BitDefenderGen:Variant.Razy.696787
NANO-AntivirusTrojan.Win32.Yakes.emsnae
MicroWorld-eScanGen:Variant.Razy.696787
TencentMalware.Win32.Gencirc.10b54b43
Ad-AwareGen:Variant.Razy.696787
SophosML/PE-A + Mal/Cerber-B
ComodoTrojWare.Win32.Ransom.Cerber.FJ@6wjqwh
BitDefenderThetaGen:NN.ZexaF.34628.Oq1@aC2egom
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CERBER.F117CM
McAfee-GW-EditionBehavesLike.Win32.Ransomware.jh
FireEyeGeneric.mg.9aa50b1857be5611
EmsisoftGen:Variant.Razy.696787 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.brfwj
WebrootW32.Trojan.Gen
AviraTR/Crypt.ZPACK.Gen7
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/Cerber!rfn
ArcabitTrojan.Razy.DAA1D3
AegisLabTrojan.Win32.Zerber.j!c
GDataGen:Variant.Razy.696787
AhnLab-V3Win-Trojan/Cerber.Gen
Acronissuspicious
McAfeeRansomware-CBER!9AA50B1857BE
MAXmalware (ai score=89)
VBA32BScope.Trojan.Encoder
MalwarebytesMalware.AI.1727767629
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_CERBER.F117CM
RisingRansom.Cerber!8.3058 (TFE:dGZlOgPtIAzGYzD6Rg)
YandexTrojan.GenAsa!1Er/jIH2Ld0
IkarusTrojan.Crypt
FortinetW32/Kryptik.HGZD!tr
AVGWin32:Trojan-gen
Qihoo-360Win32/Ransom.Cerber.HxQB8ZUA

How to remove Razy.696787?

Razy.696787 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment