Malware

Razy.18501 removal tips

Malware Removal

The Razy.18501 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.18501 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)

How to determine Razy.18501?


File Info:

name: 0133D49FFBFBE8229D6F.mlw
path: /opt/CAPEv2/storage/binaries/0745893e92eb132ba4e49edc71d6847579ccbb470f4a8ad2fcc5f69434e283fa
crc32: 555102D4
md5: 0133d49ffbfbe8229d6f2f17f0d0d661
sha1: 475258432277b9401c6ee86634f1bdcef76cd8dd
sha256: 0745893e92eb132ba4e49edc71d6847579ccbb470f4a8ad2fcc5f69434e283fa
sha512: 5f2c42c51a0fdf6485eac08fb1355085675743d8269f14a677a35a4325ba48c14c6e20cbe3eab9c785f209cdd5852aff35d7a112f3fcfa4b9276133d453a33ec
ssdeep: 1536:MThmY91ZjorIsNLI78F0MGaZhWdoyMFVq5JaE0k9nqp9988PR5:nI1Z0NLm8BTTWdo1kB508I
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18D93E0122CD441A1C7FB0F34743B5AD0CAF95521F51AB279683C7A1A7EF072DAE4AA34
sha3_384: 847854f859270c4c76e0f996abd954bbf8fc168289a9c5b39c0fb73ea4a5b891e35563ed3171279a39d547969a617b95
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-09-06 15:18:55

Version Info:

Translation: 0x0000 0x04b0
Comments: Seedy Betrustment
CompanyName: Toyish
FileDescription: Verbarreata
FileVersion: 2356.3715.9369.1784
InternalName: jj.exe
LegalCopyright: ® Wincey
LegalTrademarks: ® Wincey
OriginalFilename: jj.exe
ProductName: Foreread Anorthoclase
ProductVersion: 2356.3715.9369.1784
Assembly Version: 8565.5190.7813.5336

Razy.18501 also known as:

BkavW32.AIDetectNet.01
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.18501
FireEyeGeneric.mg.0133d49ffbfbe822
SangforTrojan.Win32.Save.a
BitDefenderGen:Variant.Razy.18501
Cybereasonmalicious.ffbfbe
CyrenW32/MSIL_Troj.CDF.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.HWJ
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Backdoor.Win32.Generic
AvastWin32:BackdoorX-gen [Trj]
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:mqDQYKVGaJgrE1gdnR9vtA)
Ad-AwareGen:Variant.Razy.18501
SophosML/PE-A + Troj/MSIL-IVQ
DrWebTrojan.PWS.Multi.1730
VIPREGen:Variant.Razy.18501
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Razy.18501 (B)
SentinelOneStatic AI – Malicious PE
GDataMSIL.Trojan.Injector.KF
AviraHEUR/AGEN.1202088
ArcabitTrojan.Razy.D4845
MicrosoftBackdoor:Win32/Bladabindi!ml
GoogleDetected
AhnLab-V3Win-Trojan/MDA.19171308.X1376
Acronissuspicious
ALYacGen:Variant.Razy.18501
MAXmalware (ai score=80)
CylanceUnsafe
IkarusTrojan.MSIL.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Injector.MHG!tr
BitDefenderThetaGen:NN.ZemsilF.34646.fm0@amGi9LiG
AVGWin32:BackdoorX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Razy.18501?

Razy.18501 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment