Malware

How to remove “Razy.709930”?

Malware Removal

The Razy.709930 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.709930 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Unconventionial language used in binary resources: Arabic (Morocco)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Razy.709930?


File Info:

name: 9EF5CC7EEAE911986C30.mlw
path: /opt/CAPEv2/storage/binaries/7044201492522028ce43df28a50fcddc24fc8ebf99f9cbaa9b3042e9577e3a9e
crc32: 17E285F2
md5: 9ef5cc7eeae911986c309d4e560b7442
sha1: 0be489fc9c512fef317eaa23a9a6b56787f566f0
sha256: 7044201492522028ce43df28a50fcddc24fc8ebf99f9cbaa9b3042e9577e3a9e
sha512: 22f24f6f072ec8dd5d9f49860d9f557e514e499ff9725070d0cc1196aaf27f31a9e33ec2bdedc5e032ed62f77a8c20469ae5ebf74995bd43e371537ccbd5c72d
ssdeep: 3072:KBALtPFtficrHQV3hdOCxlrUjT5fCl7sPiSBFEA0HPtCfPW:K2LtttfzrHQthplrUjTMl78+Sf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BC141286BFC48B82D2A39674C30F1695EB7FB6ABC421CB41AF444A25D165E96E4F00C5
sha3_384: 28233874a4c41aba86618ce71fecea83fe5cbc8be777d3c5448e708e3c8f9b9e720e226b55bb484d0415a23b51961be6
ep_bytes: 68e2108018e890b5030066890c248954
timestamp: 2009-03-17 10:55:04

Version Info:

CompanyName: SOFTWIN S.R.L.
FileDescription: Update message.
FileVersion: 1.0.0.5
InternalName: OD.exe
LegalCopyright: ©

Razy.709930 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.709930
ClamAVWin.Packed.Zbot-9855509-0
ALYacGen:Variant.Razy.709930
ZillyaTrojan.Zbot.Win32.19201
K7AntiVirusTrojan ( 0055dd191 )
K7GWTrojan ( 0055dd191 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Zbot.AD.gen!Eldorado
ESET-NOD32a variant of Win32/Kryptik.DEA
APEXMalicious
CynetMalicious (score: 100)
KasperskyPacked.Win32.Krap.hl
BitDefenderGen:Variant.Razy.709930
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:MalOb-AM [Cryp]
TencentWin32.Packed.Krap.Iqil
Ad-AwareGen:Variant.Razy.709930
EmsisoftGen:Variant.Razy.709930 (B)
ComodoTrojWare.Win32.Spy.Zbot.ACI@1rymmb
DrWebTrojan.Proxy.18036
VIPREGen:Variant.Razy.709930
TrendMicroTROJ_DLOADR.BAK
McAfee-GW-EditionGeneric PWS.go
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.9ef5cc7eeae91198
SophosML/PE-A + Mal/Zbot-AH
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Razy.709930
JiangminTrojanSpy.Zbot.adbq
WebrootW32.Malware.Gen
AviraTR/Kryptik.DEA
MAXmalware (ai score=86)
ArcabitTrojan.Razy.DAD52A
MicrosoftPWS:Win32/Zbot.gen!Y
GoogleDetected
AhnLab-V3Trojan/Win32.Zbot.R58041
McAfeeGeneric PWS.go
VBA32Malware-Cryptor.General.3
MalwarebytesMalware.Heuristic.1001
TrendMicro-HouseCallTROJ_DLOADR.BAK
RisingMalware.Zbot!8.E95E (TFE:1:8m8am7rlevE)
YandexTrojan.GenAsa!xS61vmHa4tA
IkarusPacker.Win32.Krap
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.AJ!tr
BitDefenderThetaGen:NN.ZexaF.34698.ly0@aClZcxmG
AVGWin32:MalOb-AM [Cryp]
Cybereasonmalicious.eeae91
PandaTrj/CI.A

How to remove Razy.709930?

Razy.709930 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment