Malware

Razy.800193 (B) removal tips

Malware Removal

The Razy.800193 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.800193 (B) virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Razy.800193 (B)?


File Info:

crc32: 81C36E83
md5: 09e9305d70339c6a700b41352fa3ae8a
name: 09E9305D70339C6A700B41352FA3AE8A.mlw
sha1: f1c6939e454e8e06c4862a6df2b3ee933a59a5da
sha256: 9bf4e24ef3974f7385fa3c3f71a318695c9ea9ef8d00dde360bedf420a9fc9fb
sha512: d90bb10a290c5c581ebc0999fa58b96b16a54909917c0d3f044c0df65d71f70672d01bb060c91c387566c0e9784f626605d6770720ee11c45290f8d614b33294
ssdeep: 3072:J2ZxPXWHms5JbMUEy69jqQ4Cb/H/4mi84tgVchKKJUyWul:J2vXWHm3UErOQHz/4IHiU
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 2003-2016 Glarysoft Ltd
InternalName: FileEncrypt.exe
FileVersion: 5, 0, 0, 35
CompanyName: Glarysoft Ltd
ProductName: Glary Utilities
ProductVersion: 5.0.0.1
FileDescription: File Encrypter and Decrypter
OriginalFilename: FileEncrypt.exe
Translation: 0x0804 0x03a8

Razy.800193 (B) also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
FireEyeGeneric.mg.09e9305d70339c6a
McAfeeGenericRXAA-AA!09E9305D7033
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.Razy.800193
K7GWSpyware ( 0040f0131 )
K7AntiVirusSpyware ( 0040f0131 )
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
MicroWorld-eScanGen:Variant.Razy.800193
Ad-AwareGen:Variant.Razy.800193
EmsisoftGen:Variant.Razy.800193 (B)
F-SecureHeuristic.HEUR/AGEN.1139560
McAfee-GW-EditionBehavesLike.Win32.Dropper.vt
SophosML/PE-A + Mal/EncPk-APV
AviraHEUR/AGEN.1139560
MAXmalware (ai score=81)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Qbot.MT!MTB
ArcabitTrojan.Razy.DC35C1
GDataGen:Variant.Razy.800193
BitDefenderThetaGen:NN.ZedlaF.34670.eM8@aq2XhVpj
VBA32BScope.Trojan.Encoder
ESET-NOD32a variant of Win32/GenKryptik.EXVO
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_80%
FortinetW32/Kryptik.HDNN!tr
Paloaltogeneric.ml
Qihoo-360HEUR/QVM40.1.B8AB.Malware.Gen

How to remove Razy.800193 (B)?

Razy.800193 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment