Malware

Razy.729793 (B) (file analysis)

Malware Removal

The Razy.729793 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.729793 (B) virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Razy.729793 (B)?


File Info:

crc32: 50D8E90A
md5: 8b00590df905c5117818aa682a9c6175
name: sendhookfile.exe
sha1: 80bb0e3c3ca6eab6693732e3ec81881b2e567236
sha256: e7cae3ae8ca5aa8ad3d6f27352533021da4037491747c7dbea60c7ea638b3724
sha512: 09a91515e71e17116afbc75443157e3a629ab5285a0d78eae27b1817029f6c7f492dd6435216f5b36856b9ce2ec973fee3b1f701dc823f2556b0fe0e0bcc023d
ssdeep: 192:enUrtAwKbLq0+4E0f5OpWLv7yUJ1LHpYZX2fWqraUBSqrD0zWXzGBalgsCxv:vWq0+j0kWDplHpYZXtqraUEqrDaxMS
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2020
Assembly Version: 1.0.0.0
InternalName: sendhookfile.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: StealerBin
ProductVersion: 1.0.0.0
FileDescription: StealerBin
OriginalFilename: sendhookfile.exe

Razy.729793 (B) also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.729793
FireEyeGen:Variant.Razy.729793
ALYacGen:Variant.Razy.729793
CylanceUnsafe
K7AntiVirusPassword-Stealer ( 0056b94d1 )
BitDefenderGen:Variant.Razy.729793
K7GWPassword-Stealer ( 0056b94d1 )
Invinceaheuristic
BitDefenderThetaGen:NN.ZemsilF.34152.am0@aW6IOPp
F-ProtW32/MSIL_Agent.BIL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/PSW.Agent.RXV
TrendMicro-HouseCallTROJ_GEN.R002C0DHB20
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan-PSW.MSIL.Stealer.gen
AlibabaTrojanPSW:MSIL/Dcstl.9a95564b
AegisLabTrojan.MSIL.Stealer.i!c
APEXMalicious
TencentMsil.Trojan-qqpass.Qqrob.Dztg
Ad-AwareGen:Variant.Razy.729793
SophosMal/Generic-S
DrWebTrojan.PWS.StealerNET.70
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DHB20
FortinetMSIL/Discord.GS!tr.pws
EmsisoftGen:Variant.Razy.729793 (B)
CyrenW32/MSIL_Agent.BIL.gen!Eldorado
JiangminTrojan.PSW.MSIL.anea
MAXmalware (ai score=86)
Antiy-AVLTrojan[PSW]/MSIL.Stealer
ArcabitTrojan.Razy.DB22C1
AhnLab-V3Trojan/Win32.Stealer.C4179550
ZoneAlarmHEUR:Trojan-PSW.MSIL.Stealer.gen
MicrosoftPWS:MSIL/Dcstl.GA!MTB
McAfeePWS-FCPQ!8B00590DF905
VBA32TScope.Trojan.MSIL
MalwarebytesSpyware.PasswordStealer
PandaTrj/GdSda.A
RisingStealer.Agent!8.C2 (CLOUD)
SentinelOneDFI – Malicious PE
GDataGen:Variant.Razy.729793
AVGWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Generic/Trojan.PSW.497

How to remove Razy.729793 (B)?

Razy.729793 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment