Malware

Razy.793386 removal tips

Malware Removal

The Razy.793386 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.793386 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization

How to determine Razy.793386?


File Info:

name: 69A5567F4C85133BC2A3.mlw
path: /opt/CAPEv2/storage/binaries/5cfca893c0aba3ecbd3a1689511a9b0cbca39d445f89e1c29ebafd1705be07a5
crc32: DE0E01C5
md5: 69a5567f4c85133bc2a3ea000c16d7f7
sha1: 5dab6260c86592c8778851b8e55e386924702ba2
sha256: 5cfca893c0aba3ecbd3a1689511a9b0cbca39d445f89e1c29ebafd1705be07a5
sha512: 4d3b0a7fd9512c96695b01925a0c6befb2a1af5b40874bbfbd09f922abaa76294c7e8e62cae348d94603eee3bea3c8cd6483738cf21f430bf3c1e16df1b33265
ssdeep: 3072:bsp+IXlm5IVA5EOnaCPOXFTzdc3DQlA80a:bsp+IVmKVAXnPO1dc3G0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T165C33A39F870E265C49181FA7D98E6AA8468BA30E21C355336C13F0A1D745EECC79F87
sha3_384: 27ba82cb8c9eb51f67170094d6c554477c123aefc3800f92d035823bb4c6a74e7ef99341211aec5a7aed164cdbb8be40
ep_bytes: e8c2040000e92a2d0000558bec8b4508
timestamp: 2018-10-16 23:10:48

Version Info:

0: [No Data]

Razy.793386 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.69a5567f4c85133b
McAfeeGenericRXOL-NK!69A5567F4C85
CylanceUnsafe
Cybereasonmalicious.f4c851
BitDefenderThetaGen:NN.ZexaF.34114.huW@aKI80Oii
CyrenW32/Trojan.GGF.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HHCQ
APEXMalicious
KasperskyHEUR:Backdoor.Win32.Mokes.pef
BitDefenderGen:Variant.Razy.793386
MicroWorld-eScanGen:Variant.Razy.793386
AvastWin32:Trojan-gen
RisingTrojan.Injector!1.D328 (CLASSIC)
Ad-AwareGen:Variant.Razy.793386
EmsisoftGen:Variant.Razy.793386 (B)
ComodoMalCrypt.Indus!@1qrzi1
DrWebTrojan.DownLoader36.36138
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Razy.793386
JiangminBackdoor.Mokes.cxm
AviraHEUR/AGEN.1139726
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Malware/Win.Generic.R374751
VBA32BScope.Backdoor.Mokes
ALYacGen:Variant.Razy.793386
MAXmalware (ai score=85)
MalwarebytesMachineLearning/Anomalous.97%
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.ACGU!tr
AVGWin32:Trojan-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_80% (W)

How to remove Razy.793386?

Razy.793386 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment