Malware

Should I remove “Razy.763347 (B)”?

Malware Removal

The Razy.763347 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.763347 (B) virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The executable is compressed using UPX

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Razy.763347 (B)?


File Info:

crc32: 0EE48843
md5: cc0e3a322e1ff0873e5dfa71d14a3f01
name: CC0E3A322E1FF0873E5DFA71D14A3F01.mlw
sha1: a42be6ba28bd7463586fffda69982a002b5d6d84
sha256: f784ca276fd6aeec66583d77bdb2efcccaa8d94c53810da777d4b59e5679343c
sha512: b5f07cb92ac8b86f4198960f12c505e9bfa3d01213719dd04239462171c650280908cadd49257a46831b16c86405152d86bd965814fe40509a7f642505a10145
ssdeep: 768:G7RBhwxj2Mtj7EELw/7a1vhMPeO7xdWUAohfjiT5ediYqdvDtD51pl2E:Glo2MtVMjS5MPvL0qfWT5MAbXpY
type: PE32 executable (Unknown subsystem 0x0) Unknown processor type 0x0 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

LegalCopyright: ? Microsoft Corporation. All rights reserved.
InternalName:
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
CompanyName: Microsoft Corporation
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: Microsoft? Windows? Operating System
SpecialBuild:
ProductVersion: 6.1.7600.16385
FileDescription: Windows Enhanced Storage Password Authentication Program
OriginalFilename: EhStorAuthn.exe
Translation: 0x0804 0x04b0

Razy.763347 (B) also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader18.16955
ClamAVWin.Malware.38aba-9860044-0
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacGen:Variant.Razy.763347
MalwarebytesNimnul.Virus.FileInfector.DDS
SangforTrojan.Win32.Save.a
Cybereasonmalicious.22e1ff
BaiduWin32.Trojan.ServStart.ax
CyrenW32/Nitol.K.gen!Eldorado
SymantecSMG.Heur!gen
APEXMalicious
AvastWin32:Nitol-A [Trj]
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.PornoBlocker.ejtx
BitDefenderGen:Variant.Razy.763347
NANO-AntivirusTrojan.Win32.MicroFake.cchebz
MicroWorld-eScanGen:Variant.Razy.763347
TencentTrojan.Win32.Lapka.bw
SophosML/PE-A
ComodoTrojWare.Win32.Nitol.KA@6cq5hu
BitDefenderThetaGen:NN.ZedlaF.34088.aC4@aqpv5Bei
VIPREBehavesLike.Win32.Malware.wsc (mx-v)
TrendMicroDDoS.Win32.NITOL.SMG
McAfee-GW-EditionBehavesLike.Win32.Fake.km
FireEyeGen:Variant.Razy.763347
EmsisoftGen:Variant.Razy.763347 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.ovbd
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASBOL.791
MicrosoftDDoS:Win32/Nitol.P!bit
ArcabitTrojan.Razy.DBA5D3
GDataWin32.Trojan.Microfake.A
AhnLab-V3Trojan/Win32.PornoBlocker.C4226100
Acronissuspicious
McAfeeGenericRXEN-BW!CC0E3A322E1F
MAXmalware (ai score=82)
TrendMicro-HouseCallDDoS.Win32.NITOL.SMG
RisingTrojan.Nitol!1.C6A5 (CLASSIC)
YandexTrojan.GenAsa!dzjt+DN9mv0
IkarusTrojan.Win32.MicroFake
AVGWin32:Nitol-A [Trj]

How to remove Razy.763347 (B)?

Razy.763347 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment