Malware

Razy.213629 (B) information

Malware Removal

The Razy.213629 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.213629 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Created a process from a suspicious location

How to determine Razy.213629 (B)?


File Info:

name: 4B9BA3A36C6DE9EA7BE4.mlw
path: /opt/CAPEv2/storage/binaries/e6cd20e17dd676c2d52436ed2acd14faf68291cbdc86406607f7c1e9e670aa71
crc32: 5DEA004E
md5: 4b9ba3a36c6de9ea7be4d97be9144a02
sha1: 5bdb90b5e2c0eaec33f507d95825a978b6de444a
sha256: e6cd20e17dd676c2d52436ed2acd14faf68291cbdc86406607f7c1e9e670aa71
sha512: 52b4d8efe374f6aabd3eb4102d908bd72ccee8bf896b58fe1e7cc48df6852080b13f915018160d6e60d029da0e66e55a4e871c0fc07eca266ff7c43b601fb4d4
ssdeep: 24576:kcnotAnSWuPB2EQKmiZPM1O/DP+/ZacIWhIACg0sqlW:kcnlnooEbmiZPM1u7/WhIhgmlW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F7153351E676642DC8E3BBBB2D42D7AC7323C565A95C4F782D307E1F09BAAC66C00125
sha3_384: 81e08349e496125a8cd2954d9afcda67bab243df814bfbcafc43cfc0206cfcb0a90fc8768302a30b6599ecc91f406c0d
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-01-11 22:48:37

Version Info:

Translation: 0x0000 0x04b0
CompanyName: magicbluster
FileDescription: bridgedangerous
FileVersion: 18.29.59.73
InternalName: flophouse.exe
LegalCopyright: scream © carnivore
OriginalFilename: flophouse.exe
ProductName: block
ProductVersion: 18.29.59.73
Assembly Version: 18.29.59.73

Razy.213629 (B) also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.213629
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
CyrenW32/MSIL_Kryptik.CRY.gen!Eldorado
SymantecScr.Malcode!gdn33
ESET-NOD32a variant of MSIL/Kryptik.PSV
APEXMalicious
KasperskyHEUR:Backdoor.Win32.Generic
BitDefenderGen:Variant.Razy.213629
MicroWorld-eScanGen:Variant.Razy.213629
AvastWin32:RATX-gen [Trj]
Ad-AwareGen:Variant.Razy.213629
SophosML/PE-A
ComodoTrojWare.MSIL.Boilod.MFC@7j93d6
F-SecureTrojan.TR/Dropper.MSIL.Gen
DrWebBackDoor.Quasar.1
TrendMicroBackdoor.MSIL.BLADABINDI.SMWA
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.4b9ba3a36c6de9ea
EmsisoftGen:Variant.Razy.213629 (B)
IkarusTrojan.MSIL.Krypt
GDataGen:Variant.Razy.213629
AviraTR/Dropper.MSIL.Gen
ArcabitTrojan.Razy.D3427D
MicrosoftTrojan:MSIL/Remcos.PH!MTB
AhnLab-V3Malware/Win32.RL_Generic.C4252852
McAfeePacked-PM!4B9BA3A36C6D
MAXmalware (ai score=86)
MalwarebytesMachineLearning/Anomalous.100%
TrendMicro-HouseCallBackdoor.MSIL.BLADABINDI.SMWA
RisingMalware.Obfus/MSIL@AI.100 (RDM.MSIL:WvId8rgurBUvMmD7SIF2wQ)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/CoinMiner.DTL!tr
BitDefenderThetaGen:NN.ZemsilF.34114.6m0@ae7JJ5f
AVGWin32:RATX-gen [Trj]
Cybereasonmalicious.36c6de

How to remove Razy.213629 (B)?

Razy.213629 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment