Malware

About “Razy.761599” infection

Malware Removal

The Razy.761599 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.761599 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits behavior characteristic of Cerber ransomware

How to determine Razy.761599?


File Info:

crc32: 6C1638ED
md5: b5bff131e0bedb8c7e374a9635dd54a4
name: B5BFF131E0BEDB8C7E374A9635DD54A4.mlw
sha1: b1d0745d0e53e936862ef81bb9fb7cbb75f6adc8
sha256: b3b7923c9de9d50d76e945012ad92afc354a5b4c6260b01669592fe512f0b7fd
sha512: 1e265be00a0714e42429a46bbb2947ec526d4cbe56806a7117db23ca5e3bd4f42b0b89073b020dc42524014254929d44f457ab8bc7fc378d36e6acb2dd144b07
ssdeep: 3072:AvZgCOdWXvImhZEhUCpkTHVhCGIn6domzqe2rg+h/CsAIMnzeyfpcXF2:Aj1vLvY7ie6dKrpCbI2PxX
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 Hilgraeve, Inc. 2001
InternalName: HyperTrm
FileVersion: 5.1.2600.0
CompanyName: Hilgraeve, Inc.
LegalTrademarks: HyperTerminal xae is a registered trademark of Hilgraeve, Inc.
Comments: HyperTerminal xae was developed by Hilgraeve, Inc. for M1crosoft
ProductName: M1crosoftxae Windowsxae Operating System
ProductVersion: 5.1.2600.0
FileDescription: HyperTerminal Applet
OriginalFilename: HYPERTRM.EXE
Translation: 0x0409 0x0000

Razy.761599 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004f87f21 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.5983
ClamAVWin.Ransomware.Cerber-9253780-0
CAT-QuickHealRansom.Cerber.G4
McAfeeGenericRXAI-QL!B5BFF131E0BE
CylanceUnsafe
ZillyaTrojan.Zerber.Win32.373
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 004e16c11 )
Cybereasonmalicious.1e0bed
BaiduWin32.Trojan.Kryptik.avk
SymantecPacked.Generic.459
ESET-NOD32Win32/Filecoder.Cerber.B
APEXMalicious
AvastWin32:Trojan-gen
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.761599
NANO-AntivirusTrojan.Win32.Encoder.evgsaj
SUPERAntiSpywareRansom.Cerber/Variant
MicroWorld-eScanGen:Variant.Razy.761599
TencentMalware.Win32.Gencirc.10b4af57
Ad-AwareGen:Variant.Razy.761599
SophosML/PE-A + Mal/Cerber-B
ComodoTrojWare.Win32.Kryptik.ERJ@6l0vie
BitDefenderThetaGen:NN.ZexaF.34686.xq1@am1zOgmi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPCERBER.SM3
McAfee-GW-EditionGenericRXAI-QL!B5BFF131E0BE
FireEyeGeneric.mg.b5bff131e0bedb8c
EmsisoftGen:Variant.Razy.761599 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.eahvn
WebrootW32.Trojan.Gen
AviraTR/Crypt.ZPACK.Gen7
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/Cerber.A
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Variant.Razy.761599
AhnLab-V3Win-Trojan/Cerber.Gen
Acronissuspicious
VBA32BScope.Trojan.Yakes
MAXmalware (ai score=100)
MalwarebytesMalware.AI.3152904911
PandaGeneric Suspicious
TrendMicro-HouseCallRansom_HPCERBER.SM3
RisingRansom.Cerber!8.3058 (TFE:dGZlOgWdVZ4BOl1lyQ)
YandexTrojan.GenAsa!dw3A/byAbR0
IkarusTrojan.Win32.Filecoder
FortinetW32/Kryptik.HEKH!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Razy.761599?

Razy.761599 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment