Malware

Razy.692182 malicious file

Malware Removal

The Razy.692182 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.692182 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • A named pipe was used for inter-process communication
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Razy.692182?


File Info:

crc32: 26AA0B9B
md5: 00f8387c279476fc85c641ff7a646a30
name: 88888.png
sha1: 148c84d8af8f6a1e8bcc700c1f0cc8b3336532d8
sha256: 13045d805f20db281ebabf55146c88d807d53ef5e77474f5363c0e9a636cb804
sha512: 013f65c12b91e2b7389c85cf0b4b6b54d5c06bb69fe7b8af1e9ac66a233039083409c2540626bdbd217a5ac8d0bbcf5b8c106dfd6c231ba815f6b1d1cda7736a
ssdeep: 12288:SVlQd2UML/axdZPQxjn7f1lkY1Qhe82VLYkfgn6ggK0/cm8:SG2UM73xbpl31Qw82V0kfg930C
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 2003-2016 Glarysoft Ltd
InternalName: Report.exe
FileVersion: 5, 0, 0, 6
CompanyName: Glarysoft Ltd
ProductName: Glary Utilities
ProductVersion: 5, 0, 0, 1
FileDescription: Glarysoft Crash Report
OriginalFilename: CrashReport.exe
Translation: 0x0804 0x03a8

Razy.692182 also known as:

BkavW32.AIDetectVM.malwareB
MicroWorld-eScanGen:Variant.Razy.692182
MalwarebytesBackdoor.Qbot
VIPRETrojan.Win32.Generic.pak!cobra
BitDefenderGen:Variant.Razy.692182
Cybereasonmalicious.8af8f6
Invinceaheuristic
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.EMPD
APEXMalicious
AvastFileRepMalware
KasperskyUDS:DangerousObject.Multi.Generic
RisingTrojan.Kryptik!1.C745 (CLOUD)
SophosTroj/Qbot-FS
F-SecureTrojan.TR/Crypt.ZPACK.Gen4
McAfee-GW-EditionArtemis!Trojan
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.00f8387c279476fc
EmsisoftGen:Variant.Razy.692182 (B)
AviraTR/Crypt.ZPACK.Gen4
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Wacatac.C!ml
Endgamemalicious (high confidence)
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataWin32.Backdoor.QakBot.834E8B
CynetMalicious (score: 90)
Acronissuspicious
McAfeeArtemis!00F8387C2794
VBA32BScope.TrojanRansom.Shade
CylanceUnsafe
TrendMicro-HouseCallTROJ_GEN.R002H0CFG20
SentinelOneDFI – Malicious PE
eGambitPE.Heur.InvalidSig
FortinetW32/Cridex.VHO!tr
BitDefenderThetaGen:NN.ZexaF.34128.fH1@aiYWaamj
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360HEUR/QVM19.1.F5A8.Malware.Gen

How to remove Razy.692182?

Razy.692182 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment