Malware

Razy.769735 removal instruction

Malware Removal

The Razy.769735 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.769735 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Starts servers listening on 0.0.0.0:443
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Operates on local firewall’s policies and settings
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Razy.769735?


File Info:

crc32: 9DA8BD28
md5: 782f8fd416eb8822d98d8f823959235f
name: 782F8FD416EB8822D98D8F823959235F.mlw
sha1: 5efa3da5be74388e6450ce46c4f59b52ac3dc056
sha256: 11831f3b2400978816bc852ed847ecdc7d4ce922abe3d9fb1ad554376ca838f5
sha512: 52876cf8247ba650c0d7ef92c4957a8709565c8d70421e8260a3590cc1bea71a2cec42b89afd41631926c7a7b0a5836aec4d3b15a3e9a2304958b1aaa6d34126
ssdeep: 24576:G5UxGSHd8cik3CJr0zuISZVKnigKdNCXl:GTCdYE4wunuh4
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Razy.769735 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.769735
CAT-QuickHealTrojan.MultiRI.S16413280
ALYacGen:Variant.Razy.769735
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.Razy.769735
K7GWTrojan ( 005720201 )
K7AntiVirusTrojan ( 005720201 )
CyrenW32/Cridex.Z.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:BankerX-gen [Trj]
ClamAVWin.Malware.Bankerx-9787378-0
KasperskyHEUR:Trojan-Banker.Win32.Cridex.vho
RisingTrojan.Kryptik!1.CD99 (CLASSIC)
Ad-AwareGen:Variant.Razy.769735
EmsisoftGen:Variant.Razy.769735 (B)
F-SecureHeuristic.HEUR/AGEN.1138986
DrWebTrojan.Siggen10.54948
InvinceaMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Drixed.cc
FireEyeGeneric.mg.782f8fd416eb8822
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
JiangminTrojan.Banker.Cridex.aje
AviraHEUR/AGEN.1138986
MAXmalware (ai score=89)
MicrosoftTrojan:Win32/Dridex.MS!MTB
GridinsoftTrojan.Win32.Kryptik.oa!s2
ArcabitTrojan.Razy.DBBEC7
ZoneAlarmHEUR:Trojan-Banker.Win32.Cridex.vho
GDataGen:Variant.Razy.769735
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Dridex.R353181
McAfeeDrixed-FIY!782F8FD416EB
TACHYONBanker/W32.Cridex.827392.C
MalwarebytesTrojan.Dridex
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HHAC
TencentMalware.Win32.Gencirc.11b0fffb
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.HHAC!tr
BitDefenderThetaGen:NN.ZedlaF.34634.YK4@a0NU9nli
AVGWin32:BankerX-gen [Trj]
Qihoo-360HEUR/QVM39.1.3FBB.Malware.Gen

How to remove Razy.769735?

Razy.769735 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment