Malware

Should I remove “Razy.754804”?

Malware Removal

The Razy.754804 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.754804 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Deletes its original binary from disk
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Razy.754804?


File Info:

crc32: 7796B86E
md5: a803d56b2044e029866e85c7d2fc08fc
name: A803D56B2044E029866E85C7D2FC08FC.mlw
sha1: f706bee0fa1d43c48263f5554fb325160d42825d
sha256: cd66e3369696773b2e13a7f8a2f4fd1107c2883c7a4f04ae96bd2f2d24331f30
sha512: 13f78f162baf8706643f0a648688e07804e3ce1c491e05d578980086be4e1c16b4c5ef7f44d29922c0bf30d1f8750768c787f53fcc933a76151af5c631bc04b6
ssdeep: 3072:Ivgrb+lqQ6d1xM2DbB3zS/iGit4IEWY1H0SlrLpGrqX9bOxNLtvZU:+Mb68d1BD13zS/5LpN0SxpVbOxRU
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

LegalCopyright: Copyrightxa9 1997-2011 Wayne J. Radburn
InternalName: PEview
FileVersion: 0.9.9.0
CompanyName: Wayne J. Radburn
ProductName: PEview
ProductVersion: 0.9.9.0
FileDescription: PE/COFF File Viewer
OriginalFilename: PEview.exe
Translation: 0x0409 0x04e4

Razy.754804 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.754804
FireEyeGeneric.mg.a803d56b2044e029
Qihoo-360HEUR/QVM19.1.217F.Malware.Gen
McAfeePacked-FJB!A803D56B2044
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 005722911 )
BitDefenderGen:Variant.Razy.754804
K7GWTrojan ( 005722911 )
CrowdStrikewin/malicious_confidence_100% (D)
InvinceaML/PE-A + Mal/Inject-GJ
CyrenW32/Razy.CD.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Khalesi.vho
NANO-AntivirusTrojan.Win32.Kryptik.foobtk
RisingTrojan.Kryptik!1.B34D (CLASSIC)
Ad-AwareGen:Variant.Razy.754804
SophosMal/Inject-GJ
ComodoTrojWare.Win32.Kryptik.TLS@812zm8
DrWebTrojan.Siggen10.54646
McAfee-GW-EditionBehavesLike.Win32.BadFile.cc
EmsisoftGen:Variant.Razy.754804 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.fpvzb
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.Gen3
Antiy-AVLGrayWare/Win32.Kryptik.GIFQ
MicrosoftTrojan:Win32/Glupteba.MT!MTB
GridinsoftTrojan.Heur!.03212121
ArcabitTrojan.Razy.DB8474
ZoneAlarmHEUR:Trojan.Win32.Khalesi.vho
GDataGen:Variant.Razy.754804
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Khalesi.R353882
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34590.lG2@ayec2I
ALYacGen:Variant.Razy.754804
MAXmalware (ai score=84)
VBA32Trojan.Tiggre
MalwarebytesTrojan.MalPack
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/GenKryptik.CHBV
TencentTrojan.Win32.Kryptik.gify
IkarusTrojan-Downloader.Win32.FakeAlert
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.0fa1d4
MaxSecureTrojan.Malware.121218.susgen

How to remove Razy.754804?

Razy.754804 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment