Malware

Razy.770662 removal guide

Malware Removal

The Razy.770662 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.770662 virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Detects Sandboxie through the presence of a library
  • Attempts to identify installed analysis tools by a known file location
  • Detects the presence of Wine emulator via registry key
  • Detects VirtualBox through the presence of a device
  • Detects VMware through the presence of a device
  • Checks for a known DeepFreeze Frozen State Mutex
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Razy.770662?


File Info:

crc32: 3C7BE951
md5: 14155c166d916cffa09395c34bda2d71
name: 14155C166D916CFFA09395C34BDA2D71.mlw
sha1: b3effbce5e755205a4d22daeb1203363f07ebf51
sha256: 893b90233fd5136f30b36aa75aec1f62b388486f67685497ef7eba9882d6a636
sha512: 584f4130617b61c0d4fc3436f128c37ccdb0f9d7971fedb670f50aa3a78a3843552558ba787d5851e764ed59c68b518fdb9691d6064b485c2d4d63e03be296f4
ssdeep: 3072:VqahlwqUXX7l0VjEQ3B5Zaxgxhr8tq89eAagi7GP6FwbRsvN97QoY06h5iB:4CYXKz0WxhotxwAyKcZYR6
type: MS-DOS executable

Version Info:

FileVersion: 0.6.0.3
CompanyName: InSoft
Translation: 0x0409 0x0000

Razy.770662 also known as:

K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.1915
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.770662
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.87528
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/Generic.4b315e82
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.66d916
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.NUDXLCR
APEXMalicious
AvastWin32:Zbot-PUD [Trj]
KasperskyTrojan-Spy.Win32.Zbot.yowj
BitDefenderGen:Variant.Razy.770662
NANO-AntivirusTrojan.Win32.Zbot.bdsmtw
ViRobotTrojan.Win32.A.Zbot.161264
MicroWorld-eScanGen:Variant.Razy.770662
TencentWin32.Trojan-Spy.Zbot.hpt
Ad-AwareGen:Variant.Razy.770662
SophosMal/Generic-S
ComodoMalware@#dpe1qigmoxhn
BitDefenderThetaGen:NN.ZexaF.34608.ju2@aC6QA5ni
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.14155c166d916cff
EmsisoftGen:Variant.Razy.770662 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Malware.Gen
AviraTR/Crypt.ZPACK.Gen2
eGambitPE.Heur.InvalidSig
KingsoftWin32.Heur.KVMH019.a.(kcloud)
MicrosoftPWS:Win32/Zbot
GDataGen:Variant.Razy.770662
AhnLab-V3Spyware/Win32.Zbot.R42229
Acronissuspicious
McAfeeArtemis!14155C166D91
MAXmalware (ai score=86)
VBA32TrojanSpy.Zbot
PandaTrj/Genetic.gen
TrendMicro-HouseCallHV_ZPACK_CG1540FE.RDXN
RisingRansom.Blocker!8.12A (CLOUD)
YandexTrojanSpy.Agent!+fT24Jr/6Qc
IkarusTrojan-Spy.Win32.Zbot
FortinetW32/Shiz.NCF!tr
AVGWin32:Zbot-PUD [Trj]
Qihoo-360Win32/Trojan.Zbot.HxQBqfcA

How to remove Razy.770662?

Razy.770662 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment