Malware

What is “Razy.800807”?

Malware Removal

The Razy.800807 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.800807 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Compression (or decompression)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Executed a process and injected code into it, probably while unpacking
  • Queries information on disks, possibly for anti-virtualization
  • Detects Sandboxie through the presence of a library
  • Deletes its original binary from disk
  • Likely installs a bootkit via raw harddisk modifications
  • Attempts to delete volume shadow copies
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Installs a native executable to run on early Windows boot
  • Writes a potential ransom message to disk
  • Clears Windows events or logs
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Razy.800807?


File Info:

crc32: 5800AEDA
md5: 117fdf3a2c773d70de5a7b65d269fdee
name: 117FDF3A2C773D70DE5A7B65D269FDEE.mlw
sha1: 53dd2c26fa56168b3206786bdfcd50cddf7d071d
sha256: 354770f60e4d7f200a22fba14fb8874ff5c133a5df063981028d4b21e6a5b419
sha512: d9cfd1dae125ac852bdea87f7551c3d3f5530f3ab1ce6eff00f0e26042b6aa218c3671fe66c0e38395e5fe179b9881a09589198508405d953a0a788791eb9199
ssdeep: 768:ir2+tPH+0jVPPD3TMLRFdq/DOHNbZm8MGodOr2FH/Tx6/R4bie9TJSsw1fLG5mjI:iy+1e0hPLA3cDQN/MGmOCFN8elJ1w9DC
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Razy.800807 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055e3e11 )
LionicTrojan.Win32.Satan.j!c
Elasticmalicious (high confidence)
McAfeeRDN/Ransom.cm
ZillyaTrojan.Satan.Win32.4
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Satan.6ceb68b9
K7GWTrojan ( 0055e3e11 )
Cybereasonmalicious.a2c773
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.FKKB
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Satan.p
BitDefenderGen:Variant.Razy.800807
NANO-AntivirusTrojan.Win32.Satan.eijqhn
MicroWorld-eScanGen:Variant.Razy.800807
TencentWin32.Trojan.Mbrmodifier.Auto
Ad-AwareGen:Variant.Razy.800807
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34110.dqX@aaTJbNci
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_Satan.R002C0PHP21
McAfee-GW-EditionBehavesLike.Win32.Generic.ph
FireEyeGeneric.mg.117fdf3a2c773d70
EmsisoftGen:Variant.Razy.800807 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Satan.i
AviraHEUR/AGEN.1108580
Antiy-AVLTrojan/Generic.ASMalwS.1C72088
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Dynamer!rfn
GDataGen:Variant.Razy.800807
AhnLab-V3Trojan/Win32.Satan.C2327767
Acronissuspicious
VBA32BScope.Trojan.Tiggre
MAXmalware (ai score=81)
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_Satan.R002C0PHP21
RisingTrojan.Generic@ML.97 (RDML:EaLIjZjWELdfRWvWsQmQPg)
YandexTrojan.GenAsa!P9zxCz2eaKo
IkarusTrojan.Win32.Krypt
FortinetW32/GenKryptik.KKE!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Razy.800807?

Razy.800807 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment