Malware

What is “Razy.803735 (B)”?

Malware Removal

The Razy.803735 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.803735 (B) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Crashed cuckoomon during analysis. Report this error to the Github repo.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Razy.803735 (B)?


File Info:

crc32: 1A366C78
md5: a359dcf25bb0e04651654b419a43844a
name: A359DCF25BB0E04651654B419A43844A.mlw
sha1: d52437de9f83f62a2d7b6ae35e60bdda3ce330b8
sha256: aefb3b34116ae6ef597453a0ad6cd53f772f3a3ed16f4f83aef001797bf9f4bf
sha512: 8d7fefe6c3fd07d653bfc484c02f4830273745c8d11d1798d207a02721574599e4ae6072e25607980a020211822c967752bb47f86cde5f26cc017a42dc64783c
ssdeep: 768:wQMobQTPm4eO11lp/QnDjaRPjW3U1lOi9xOqD:wQ30bVXpuDORC3U9PD
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: FAEROEERNE
FileVersion: 2.02
CompanyName: CC Pro 2019 xa9
Comments: CC Pro 2019 xa9
ProductName: CC Pro xa9
ProductVersion: 2.02
FileDescription: CC Pro xa9
OriginalFilename: FAEROEERNE.exe

Razy.803735 (B) also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.803735
FireEyeGen:Variant.Razy.803735
McAfeePWS-FCTL!A359DCF25BB0
AegisLabTrojan.Win32.Androm.m!c
SangforMalware
K7AntiVirusTrojan ( 0057482e1 )
BitDefenderGen:Variant.Razy.803735
K7GWTrojan ( 0057482e1 )
CyrenW32/Trojan.BIFE-7232
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Generic-9806459-0
KasperskyBackdoor.Win32.Androm.uibi
AlibabaBackdoor:Win32/Androm.f324fc85
ViRobotTrojan.Win32.Z.Woreflint.61440
RisingDownloader.Guloader!1.D025 (CLASSIC)
Ad-AwareGen:Variant.Razy.803735
EmsisoftGen:Variant.Razy.803735 (B)
ComodoMalware@#5jf9e36zqgfk
F-SecureTrojan.TR/AD.VBCryptor.avsmt
DrWebTrojan.Siggen11.54815
TrendMicroTrojan.Win32.MALREP.THLAOBO
McAfee-GW-EditionPWS-FCTL!A359DCF25BB0
SophosMal/Generic-S
AviraTR/AD.VBCryptor.avsmt
KingsoftWin32.Hack.Androm.ui.(kcloud)
MicrosoftTrojan:Win32/Ymacco.AAAE
GridinsoftTrojan.Win32.Downloader.oa
ArcabitTrojan.Razy.DC4397
ZoneAlarmBackdoor.Win32.Androm.uibi
GDataWin32.Trojan-Downloader.GuLoader.BNY98Y
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Injector.C4261673
ALYacGen:Variant.Razy.803735
MAXmalware (ai score=99)
MalwarebytesTrojan.MalPack.VB.Generic
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.EOBU
TrendMicro-HouseCallTrojan.Win32.MALREP.THLAOBO
YandexTrojan.Igent.bUYjHq.32
IkarusTrojan.VB.Crypt
eGambitUnsafe.AI_Score_82%
FortinetW32/EOBU!tr
WebrootW32.Trojan.Gen
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Backdoor.d7f

How to remove Razy.803735 (B)?

Razy.803735 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment