Malware

Razy.73730 removal guide

Malware Removal

The Razy.73730 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.73730 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Behavior consistent with a dropper attempting to download the next stage.
  • Exhibits behavior characteristic of Locky ransomware

Related domains:

baspcxtca.work
uttpsnmij.ru
hkjjkcw.xyz
wqeewkuq.work
yyaodfr.biz
uaxddxqtvtqwqxk.pw

How to determine Razy.73730?


File Info:

crc32: 5F1923ED
md5: 3b90e75dc1d3949fff1b7a608a2489d7
name: 3B90E75DC1D3949FFF1B7A608A2489D7.mlw
sha1: 27bdf5f8dd5fc197b78ebca3a14acd497c400653
sha256: be2fbd338192cd66f48466162d9256e2f4f89bfdfc9d85e87d55779154b57784
sha512: cd091f2ff785404ba1f4770b5fb4074f6a13acc691dbb9a8f5ede5bf486034e491c11fc66528192c40921098af76b1b335f127066eb4376af8b18212b813bff2
ssdeep: 6144:OsYL6UFyl/sYb7adVDs+1pjP3VIkV+mHE00O0Z49pQm7n:AF9Y3eVDsCphznHENLMpxb
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Razy.73730 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004f00a01 )
LionicTrojan.Win32.Injector.tn6z
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.3976
CynetMalicious (score: 100)
CAT-QuickHealRansomware.Generic.WR4
ALYacGen:Variant.Razy.73730
CylanceUnsafe
ZillyaTrojan.Injector.Win32.392532
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaVirTool:Win32/Injector.f05ade39
K7GWTrojan ( 004f00a01 )
Cybereasonmalicious.dc1d39
CyrenW32/Trojan.YCNL-0723
SymantecRansom.Locky!g9
ESET-NOD32Win32/Filecoder.Locky.C
ZonerTrojan.Win32.43219
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.73730
NANO-AntivirusTrojan.Win32.Encoder.edxzzc
ViRobotTrojan.Win32.Locky.269106.A
MicroWorld-eScanGen:Variant.Razy.73730
TencentMalware.Win32.Gencirc.114b618f
Ad-AwareGen:Variant.Razy.73730
SophosMal/Generic-R + Mal/Isda-D
ComodoMalware@#1s7mk4xfrew7q
BitDefenderThetaGen:NN.ZexaF.34050.quZ@aCR9PQhi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_LOCKY.SMR5
McAfee-GW-EditionRansomware-FOV!3B90E75DC1D3
FireEyeGeneric.mg.3b90e75dc1d3949f
EmsisoftGen:Variant.Razy.73730 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Banker.Shiotob.bc
AviraHEUR/AGEN.1120912
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.197D317
MicrosoftVirTool:Win32/Injector.IM
ArcabitTrojan.Razy.D12002
SUPERAntiSpywareRansom.Locky/Variant
GDataGen:Variant.Razy.73730
AhnLab-V3Trojan/Win32.Locky.R183982
McAfeeRansomware-FOV!3B90E75DC1D3
MAXmalware (ai score=81)
VBA32Hoax.Locky
MalwarebytesMachineLearning/Anomalous.97%
PandaTrj/CI.A
TrendMicro-HouseCallRansom_LOCKY.SMR5
RisingTrojan.Generic@ML.100 (RDML:hN00GcGMPeSHjhVKqiBdaQ)
IkarusTrojan-Ransom.Locky
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Bebloh.P!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Inject.HwoCEpsA

How to remove Razy.73730?

Razy.73730 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment