Malware

Razy.729793 removal tips

Malware Removal

The Razy.729793 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.729793 virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Razy.729793?


File Info:

crc32: B36626AF
md5: 1b1ba59eec12f333e680502af684ee9f
name: sendhookfile.exe
sha1: e60c4645afebd15e04dbebbca900b7a4d9238c3b
sha256: 1c9711c0059f07c44855745492710ac226b71b590d1e1e23f979d4c964561cfe
sha512: 41073ed3e7a1d109cc8c7875be516e4118c1cd4a94a045d7ccff0ddde307171b10d50d2dfc1bd705643be9f8671059d45ef7ff3b381a1d9fe98ec8edeb4ee7c3
ssdeep: 192:2nUrtAwKbLq0+4E0f5OpWLv7yUJ1LHpYZX2fWqraUBSqrD0zWvgBalgsCxv:nWq0+j0kWDplHpYZXtqraUEqrDaHMS
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2020
Assembly Version: 1.0.0.0
InternalName: sendhookfile.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: StealerBin
ProductVersion: 1.0.0.0
FileDescription: StealerBin
OriginalFilename: sendhookfile.exe

Razy.729793 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.729793
McAfeePWS-FCPQ!1B1BA59EEC12
VIPRETrojan.Win32.Generic!BT
K7AntiVirusPassword-Stealer ( 0056b94d1 )
BitDefenderGen:Variant.Razy.729793
K7GWPassword-Stealer ( 0056b94d1 )
Invinceaheuristic
BitDefenderThetaGen:NN.ZemsilF.34152.am0@a8Gkyvb
F-ProtW32/MSIL_Agent.BIL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/PSW.Agent.RXV
APEXMalicious
KasperskyHEUR:Trojan-PSW.MSIL.Stealer.gen
Ad-AwareGen:Variant.Razy.729793
DrWebTrojan.PWS.StealerNET.70
FortinetMSIL/Discord.GS!tr.pws
FireEyeGen:Variant.Razy.729793
CyrenW32/MSIL_Agent.BIL.gen!Eldorado
JiangminTrojan.PSW.MSIL.anea
MAXmalware (ai score=83)
Antiy-AVLTrojan[PSW]/MSIL.Stealer
ArcabitTrojan.Razy.DB22C1
ZoneAlarmHEUR:Trojan-PSW.MSIL.Stealer.gen
MicrosoftPWS:MSIL/Dcstl.GA!MTB
VBA32TScope.Trojan.MSIL
ALYacGen:Variant.Razy.729793
MalwarebytesSpyware.PasswordStealer
RisingStealer.Agent!8.C2 (TFE:dGZlOgzp1SpQ9KCm0A)
SentinelOneDFI – Malicious PE
GDataGen:Variant.Razy.729793
AVGWin32:PWSX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_70% (D)
Qihoo-360HEUR/QVM03.0.308F.Malware.Gen

How to remove Razy.729793?

Razy.729793 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment