Malware

Razy.799386 removal guide

Malware Removal

The Razy.799386 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.799386 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial binary language: Russian
  • A process attempted to delay the analysis task by a long amount of time.
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Razy.799386?


File Info:

crc32: EC87402C
md5: 6151b025ed38b0de5a2ed7e0021ddb01
name: 6151B025ED38B0DE5A2ED7E0021DDB01.mlw
sha1: 5f84c0ed82102fae784bf091c0b3f897e4357929
sha256: ab2dcc4374d9451388af42526db9ed3f6a9f3baa0d7dabb698d1fe4d2a644c98
sha512: cb77414f09446c1da16062e1b2028a3df8aed41b61607bd8deae8a3c661cee6f502a0d9c2085c7fab1d6e8b0c64bcbe262fd9c6f4fcb296c0c41656604ce64ce
ssdeep: 3072:1MX6AefalE7TAK6cMBSH9gd4QXEGFvbfU4Puq2qSZG5HgByej:11Aey6AKv2V/FDMou13Mg
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 gora
InternalName: Button For 7z SFX
FileVersion: Version of file 4.2.4 build 2000 [x86]
CompanyName: Company 'gora-sah'
PrivateBuild: 08.06.2012
LegalTrademarks: Still is not present
Comments: Button For creation and job with 7z SXF archives
ProductName: Button v4.2.4 [x86]
SpecialBuild: For all users
ProductVersion: Version of product 4.2.4 [x86]
FileDescription: 7z SFX archive tool. The last version of 'Button' you can find on http://buttontc.7zsfx.info
OriginalFilename: Button.exe
Translation: 0x0419 0x04b0

Razy.799386 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.799386
FireEyeGeneric.mg.6151b025ed38b0de
ALYacGen:Variant.Razy.799386
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_80% (D)
BitDefenderGen:Variant.Razy.799386
K7GWSpyware ( 0040f0131 )
K7AntiVirusSpyware ( 0040f0131 )
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyUDS:DangerousObject.Multi.Generic
RisingTrojan.Kryptik!8.8 (TFE:2:uVNqqgA4Ji)
Ad-AwareGen:Variant.Razy.799386
EmsisoftGen:Variant.Razy.799386 (B)
McAfee-GW-EditionArtemis!Trojan
SophosML/PE-A + Mal/EncPk-APV
eGambitUnsafe.AI_Score_99%
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Wacatac.DA!ml
GridinsoftMalware.Win32.Pack.40712!se
ArcabitTrojan.Razy.DC329A
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataGen:Variant.Razy.799386
CynetMalicious (score: 100)
McAfeeGenericRXMV-BP!6151B025ED38
MAXmalware (ai score=85)
VBA32BScope.Backdoor.Qbot
MalwarebytesSpyware.Zbot.ED
ESET-NOD32a variant of Win32/Kryptik.HHYG
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HDJM!tr
BitDefenderThetaGen:NN.ZedlaF.34670.Kz8@aajS48hi
Qihoo-360HEUR/QVM40.1.AF87.Malware.Gen

How to remove Razy.799386?

Razy.799386 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment