Malware

Razy.769185 removal tips

Malware Removal

The Razy.769185 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.769185 virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Anomalous binary characteristics

How to determine Razy.769185?


File Info:

crc32: B7CAC53A
md5: 8de050c0387e584385fc3b19a35b0c92
name: 8DE050C0387E584385FC3B19A35B0C92.mlw
sha1: 5237949eb1402d5d388687569d148f5b1e311422
sha256: e185206ae58ebf0b599194563c89078dddabfc0670e6978b9b94c1172e3af9a1
sha512: e316e121f8a191dc546b97f39aada585c3ce437b4d1c7a93904808285ca95c7ba7a954a49f4e58d312b78be3877e767d71911c54b0d47d6bf35bc2aadef0c210
ssdeep: 6144:RLeKB/GlubKZFqhBG3bLSDo6N7vzh3O61/petSyc2S:RLF+Pks3K06hl3f4cT
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: WmiApSrv.exe
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 6.1.7600.16385
FileDescription: WMI Performance Reverse Adapter
OriginalFilename: WmiApSrv.exe
Translation: 0x0409 0x04b0

Razy.769185 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebBackDoor.Qbot.540
MicroWorld-eScanGen:Variant.Razy.769185
FireEyeGeneric.mg.8de050c0387e5843
McAfeeGenericRXMN-VD!8DE050C0387E
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 0049f6ae1 )
BitDefenderGen:Variant.Razy.769185
K7GWRiskware ( 0049f6ae1 )
Cybereasonmalicious.eb1402
BitDefenderThetaGen:NN.ZexaF.34634.Gt1@a8hAY0pi
CyrenW32/Qbot.AA.gen!Eldorado
SymantecTrojan.Maltrec.TS
AvastWin32:DangerousSig [Trj]
ClamAVWin.Malware.Qbot-9779038-0
KasperskyHEUR:Trojan.Win32.Bsymem.pef
RisingTrojan.Kryptik!1.CE9B (CLASSIC)
Ad-AwareGen:Variant.Razy.769185
SophosMal/EncPk-APV
F-SecureHeuristic.HEUR/AGEN.1139338
InvinceaMal/EncPk-APV
McAfee-GW-EditionGenericRXMN-VD!8DE050C0387E
EmsisoftMalCert.A (A)
JiangminTrojanDownloader.Agent.fxwv
eGambitPE.Heur.InvalidSig
AviraHEUR/AGEN.1139338
MAXmalware (ai score=81)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Qakbot.KSH!cert
GridinsoftTrojan.Win32.Kryptik.oa!s3
ArcabitTrojan.Razy.DBBCA1
ZoneAlarmHEUR:Trojan.Win32.Bsymem.pef
GDataWin32.Packed.QBot.A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Kryptik.R353125
Acronissuspicious
VBA32BScope.TrojanRansom.Shade
ALYacGen:Variant.Razy.769185
MalwarebytesBackdoor.Qbot
PandaTrj/Genetic.gen
APEXMalicious
ESET-NOD32a variant of Win32/GenCBL.DC
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HGKG!tr
AVGWin32:DangerousSig [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Razy.769185?

Razy.769185 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment