Malware

Razy.757980 removal instruction

Malware Removal

The Razy.757980 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.757980 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Enumerates services, possibly for anti-virtualization
  • Deletes its original binary from disk
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics

Related domains:

microsoft-com.mail.protection.outlook.com

How to determine Razy.757980?


File Info:

crc32: A647A3CD
md5: 5b3dc22e97bcf0a91381900b81fb7ad0
name: 5B3DC22E97BCF0A91381900B81FB7AD0.mlw
sha1: 77dc1f4095d1516cd004f9e6288e7abd9d773288
sha256: ca476ac81edfc6a68767ea3c2715e113035955141c30a4f475e789f92d25b0ad
sha512: 4c9d331f0e713005e1f88c3d5825f8ca0dbc6187f227348b0cfda982c8e50fbbfb9d22c89117b2323b3bf7b04860341ba5b0d2b72ec5c502f6db24aca530a8e3
ssdeep: 196608:SGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGG:SGGGGGGGGGGGGGGGGGGGGGGGGGGGGGG
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Razy.757980 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader25.38311
MicroWorld-eScanGen:Variant.Razy.757980
ALYacGen:Variant.Razy.757980
MalwarebytesBackdoor.Tofsee
SangforMalware
K7AntiVirusTrojan ( 00517c911 )
BitDefenderGen:Variant.Razy.757980
K7GWTrojan ( 00517c911 )
CrowdStrikewin/malicious_confidence_100% (D)
TrendMicroRansom_CERBER.SMALY0
BitDefenderThetaGen:NN.ZexaF.34634.@tW@a0MJCke
CyrenW32/S-721a11f7!Eldorado
SymantecPacked.Generic.493
TrendMicro-HouseCallRansom_CERBER.SMALY0
AvastWin32:Evo-gen [Susp]
ClamAVWin.Malware.Locky-7090183-0
KasperskyHEUR:Backdoor.Win32.Poison.vho
NANO-AntivirusVirus.Win32.Gen.ccmw
RisingTrojan.Kryptik!1.AE8C (CLASSIC)
Ad-AwareGen:Variant.Razy.757980
EmsisoftTrojan-Ransom.Locky (A)
ComodoTrojWare.Win32.Tofsee.BJ@79g6sc
F-SecureTrojan.TR/Crypt.ZPACK.Gen4
VIPRETrojan.Win32.Generic!BT
InvinceaML/PE-A + Mal/Elenoocka-E
McAfee-GW-EditionBehavesLike.Win32.Dropper.wc
FireEyeGeneric.mg.5b3dc22e97bcf0a9
SophosMal/Elenoocka-E
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Poison.aus
AviraTR/Crypt.ZPACK.Gen4
Antiy-AVLTrojan[Backdoor]/Win32.Poison
MicrosoftBackdoor:Win32/Tofsee.T
ArcabitTrojan.Razy.DB90DC
ZoneAlarmHEUR:Backdoor.Win32.Poison.vho
GDataGen:Variant.Razy.757980
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/RansomCrypt.Exp
Acronissuspicious
McAfeeRansom-Locky!5B3DC22E97BC
MAXmalware (ai score=84)
VBA32Trojan.FakeAV.01657
CylanceUnsafe
APEXMalicious
ESET-NOD32a variant of Win32/Kryptik.HG
TencentMalware.Win32.Gencirc.10ce133d
YandexTrojan.GenAsa!keY4O/4wQ5c
IkarusTrojan-Ransom.Locky
eGambitUnsafe.AI_Score_83%
FortinetW32/Kryptik.GKVH!tr
AVGFileRepMalware
Cybereasonmalicious.e97bcf
Qihoo-360HEUR/QVM20.1.3FBB.Malware.Gen

How to remove Razy.757980?

Razy.757980 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment