Malware

Razy.766664 removal

Malware Removal

The Razy.766664 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.766664 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Collects information to fingerprint the system

How to determine Razy.766664?


File Info:

crc32: 87523AA5
md5: b9cdf7c452ac0e50fcc4bbe6f29a1d1e
name: B9CDF7C452AC0E50FCC4BBE6F29A1D1E.mlw
sha1: 68679f5d94b03d3794b37ef26a0ec78cb3738929
sha256: 747b4da6c8d535d29f2165578f407635c9284085a785acc63b44ce492cf65f2d
sha512: 880c1ce181c4e3f2b6cb88d265d76c981d45bafa09bdd2cf1fb5b7229464aa62d0c884a511ff69638870da547ea86e4063972300290f0c60c4d5871dfb6d0f68
ssdeep: 3072:J32FwgDOPsISj8XmVwpYS+NPa06Ukr+5EX9lGkwyE:F2F/06j1m2Sx06Ukr+5kfG2
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Beeps (Shin Rack) 2001-2005
InternalName: Rural
FileVersion: 3, 6, 9
CompanyName: Ahakan
ProductName: Nope
ProductVersion: 3, 6
FileDescription: Gas Nat Term
OriginalFilename: Chlqi.exe
Translation: 0x0409 0x04b0

Razy.766664 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.DownLoader7.50043
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.766664
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.2643
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
Cybereasonmalicious.452ac0
SymantecTrojan.Gen
ESET-NOD32Win32/Lyposit.A
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.kxoy
BitDefenderGen:Variant.Razy.766664
NANO-AntivirusTrojan.Win32.Blocker.btouvn
MicroWorld-eScanGen:Variant.Razy.766664
TencentWin32.Trojan.Blocker.Pikb
Ad-AwareGen:Variant.Razy.766664
SophosMal/Generic-R + Mal/EncPk-AIQ
ComodoMalware@#1nxm65jzywse4
BitDefenderThetaGen:NN.ZexaF.34670.gmKfaCRmR!ai
VIPRETrojan.Win32.Lyposit.ba (v)
McAfee-GW-EditionPWS-Zbot-FANY!B9CDF7C452AC
FireEyeGeneric.mg.b9cdf7c452ac0e50
EmsisoftGen:Variant.Razy.766664 (B)
JiangminTrojan/Blocker.hnf
WebrootW32.Rogue.Gen
AviraHEUR/AGEN.1101722
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Ditertag.A
GDataGen:Variant.Razy.766664
Acronissuspicious
McAfeePWS-Zbot-FANY!B9CDF7C452AC
MAXmalware (ai score=81)
VBA32Malware-Cryptor.ImgChk
MalwarebytesMalware.Heuristic.1003
PandaTrj/CI.A
RisingRansom.Lyposit!8.1E79 (CLOUD)
YandexTrojan.Blocker!WY++ld3ecEs
IkarusTrojan-PWS.Win32.Zbot
FortinetW32/Kryptik.ASJO!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HxIBEpsA

How to remove Razy.766664?

Razy.766664 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment