Malware

Razy.794939 information

Malware Removal

The Razy.794939 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.794939 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • .NET file is packed/obfuscated with SmartAssembly
  • Authenticode signature is invalid
  • Attempts to remove evidence of file being downloaded from the Internet
  • Sniffs keystrokes
  • Creates known Quasar mutexes

How to determine Razy.794939?


File Info:

name: 7AF125F5DE1ABA0032B9.mlw
path: /opt/CAPEv2/storage/binaries/35959f2b7b17ea25a207da949913fe6caa57c1bc1ad57c130c4edf3a8b06060b
crc32: 4E1ADF78
md5: 7af125f5de1aba0032b9d34ed9542904
sha1: a88e863ce924b2f85d14f9379009fce39f4dffab
sha256: 35959f2b7b17ea25a207da949913fe6caa57c1bc1ad57c130c4edf3a8b06060b
sha512: bb26ec82b525b44677fcc266db7e53a7428c010f4ff73ca020a679174e49e159979c5fd22da4bcb64781f1f643871ffc67247bd58f9f2d9418efbb6cda3f9f16
ssdeep: 3072:H/CU6HkcpkVnd+qXNkitwcCigMBDnOj23xrxn5I57/g/gZ7eFdJ:fQ/iYql5lBrOjEjna57Ogh0d
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A2445A18A3AB0522FBD773F8E9A54791426A7D54550EE38698F4309F1EBE767CC00A0F
sha3_384: 30e23436449d9182a1c139508f88a13e46127f635c191c571fdcb9df8a81d7c2c1becc2d50f03333e69f3b14f8bc744a
ep_bytes: ff250020400000000000000000000000
timestamp: 2015-12-27 02:05:47

Version Info:

Translation: 0x0000 0x04b0
FileDescription: sound_driver
FileVersion: 1.0.0.0
InternalName: sound_driver.exe
LegalCopyright: Copyright © 2015
OriginalFilename: sound_driver.exe
ProductName: sound_driver
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Razy.794939 also known as:

LionicTrojan.MSIL.Quasar.l!c
Elasticmalicious (high confidence)
DrWebBackDoor.QuasarNET.1
MicroWorld-eScanGen:Variant.Razy.794939
FireEyeGeneric.mg.7af125f5de1aba00
ALYacGen:Variant.Razy.794939
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.MSIL.Quasar.gen
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:MSIL/Quasar.d631a57e
K7GWTrojan ( 0051a4881 )
K7AntiVirusTrojan ( 0051a4881 )
BitDefenderThetaGen:NN.ZemsilF.34182.pm0@aelmMTf
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.LEW
TrendMicro-HouseCallTROJ_GEN.R002C0PJT21
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Spy.MSIL.Quasar.gen
BitDefenderGen:Variant.Razy.794939
AvastWin32:RATX-gen [Trj]
TencentMalware.Win32.Gencirc.11c53a1c
SophosMal/Generic-S
ComodoMalware@#2dui5ydrh7fz
ZillyaTrojan.GenKryptik.Win32.6226
TrendMicroTROJ_GEN.R002C0PJT21
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
EmsisoftGen:Variant.Razy.794939 (B)
IkarusTrojan.MSIL.Injector
JiangminTrojanSpy.MSIL.rvn
AviraTR/Crypt.XPACK.Gen8
MAXmalware (ai score=84)
Antiy-AVLTrojan[Spy]/MSIL.Quasar
MicrosoftBackdoor:Win32/Bladabindi!ml
ZoneAlarmHEUR:Trojan-Spy.MSIL.Quasar.gen
GDataGen:Variant.Razy.794939
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C1366635
McAfeeGenericRXEQ-MS!7AF125F5DE1A
VBA32TScope.Trojan.MSIL
APEXMalicious
RisingTrojan.Generic/MSIL@AI.95 (RDM.MSIL:7zKpdIayZZIVUtYRPg+7WQ)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.73695559.susgen
FortinetMSIL/Kryptik.LEW!tr
AVGWin32:RATX-gen [Trj]
Cybereasonmalicious.5de1ab
PandaTrj/CI.A

How to remove Razy.794939?

Razy.794939 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment