Malware

Razy.789071 removal tips

Malware Removal

The Razy.789071 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.789071 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Exhibits behavior characteristic of iSpy Keylogger

How to determine Razy.789071?


File Info:

crc32: E0CB766F
md5: ed794575d9cd53218b54a3a0a763ea19
name: ED794575D9CD53218B54A3A0A763EA19.mlw
sha1: 82f59f03aadb86da1bad9f8c1d42be4e8e12409e
sha256: 91b22c2bb197dc5789f469022e42e77a85eadbe08a063bb5cf54f673b06cd70c
sha512: 1725014ec088dc49cb914e7a846913e83c424dfa66e8b2e17c9ecb3f6610ad368f192493030da1d6cfdbb444ca3635d1a234a5392f961cfc638690528d8f2231
ssdeep: 24576:QyYOWdGJ49BkyVn0s/rRi/VND+fseU2AvF/:rYOZMX908i/3+0ea9
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: Copyright 1998-2015 by Neil Hodgson
InternalName: SciTE
FileVersion: 3.5.4
CompanyName: Neil Hodgson neilh@scintilla.org
ProductName: SciTE
ProductVersion: 3.5.4
FileDescription: SciTE Lite - a Scintilla based Text Editor modified by Jos for AutoIt3.
OriginalFilename: SciTE.EXE

Razy.789071 also known as:

K7AntiVirusTrojan ( 004d39161 )
Elasticmalicious (high confidence)
DrWebBackDoor.Comet.2020
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.789071
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.38511
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/runner.ali1000123
K7GWTrojan ( 004d39161 )
Cybereasonmalicious.5d9cd5
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.DNB
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Packed.Razy-6849099-0
KasperskyTrojan-Ransom.Win32.Blocker.dvjn
BitDefenderGen:Variant.Razy.789071
NANO-AntivirusTrojan.Win32.Blocker.eqhpmw
MicroWorld-eScanGen:Variant.Razy.789071
TencentWin32.Trojan.Blocker.Amvx
Ad-AwareGen:Variant.Razy.789071
SophosML/PE-A + Troj/MSIL-JHH
BitDefenderThetaGen:NN.ZemsilF.34628.Ir3@a4CkOyei
VIPRETrojan.Win32.Generic!BT
FireEyeGeneric.mg.ed794575d9cd5321
EmsisoftGen:Variant.Razy.789071 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.Gen
MicrosoftBackdoor:Win32/Fynloski.A
AegisLabTrojan.Win32.Blocker.j!c
GDataGen:Variant.Razy.789071
McAfeeArtemis!ED794575D9CD
MAXmalware (ai score=89)
VBA32TScope.Trojan.MSIL
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/GdSda.A
IkarusTrojan-Spy.Agent
FortinetMSIL/Injector.MEG!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HwMA53YA

How to remove Razy.789071?

Razy.789071 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment