Malware

Razy.805112 removal instruction

Malware Removal

The Razy.805112 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.805112 virus can do?

  • Presents an Authenticode digital signature
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Razy.805112?


File Info:

name: 29B24AAFB947722CED6A.mlw
path: /opt/CAPEv2/storage/binaries/922f2728396c83b43bfb409d628115cdb2dd143a614acc1bfd80114f73acdb0a
crc32: 8A3678F4
md5: 29b24aafb947722ced6ac1ef2b117a8c
sha1: 00525ab43354f766563da9dedc64056fcd75076c
sha256: 922f2728396c83b43bfb409d628115cdb2dd143a614acc1bfd80114f73acdb0a
sha512: 573f6e025b02aacaf5caa08ec06ba1eb686f4824c37472309b9a72ba4f806fa538c9bbb08bbec0259c6ba45b47a62bbbeabea531bccff72efec35434d1e63d45
ssdeep: 24576:XhqwCMm5PyaT85eHNbJEMQHJeU4ak+FD5oN8WIZdCNvBPk76R4Seaqvoo3GNfJ:XhqwCMm5PyaT85eHNb+MQHJeU4ak+FDE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E2551B2E6289CE07C4D87D77CAD5D6152F19ED811E004A6A0219FD939EBF6CBADCC207
sha3_384: a5e49b0bb0da24e3bd2153e8d87853f37a79434d59dec65ae098c5bd7fb6db32bc8508f9c4f466057dbb483bfc50fd36
ep_bytes: ff250020400000000000000000000000
timestamp: 1981-02-21 21:30:15

Version Info:

CompanyName: Wondershare
FileDescription: Wondershare Filmora X
FileVersion: .
InternalName: Wondershare Filmora X.exe
LegalCopyright: Copyright (c) 2020 Wondershare. All rights reserved.
OriginalFilename: Wondershare Filmora X.exe
ProductName: Wondershare Filmora
ProductVersion: .
Translation: 0x0804 0x04b0

Razy.805112 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Siggen11.49456
MicroWorld-eScanGen:Variant.Razy.805112
FireEyeGeneric.mg.29b24aafb947722c
McAfeePWS-FCRY!29B24AAFB947
CylanceUnsafe
SangforTrojan.Win32.Wacatac.B
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanSpy:MSIL/Stealer.6222d0b7
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.fb9477
BitDefenderThetaGen:NN.ZemsilF.34212.vn2@aWx18zcb
CyrenW32/MSIL_Kryptik.CRP.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of MSIL/Kryptik.YUS
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan-Spy.MSIL.Stealer.gen
BitDefenderGen:Variant.Razy.805112
NANO-AntivirusTrojan.Win32.Stealer.igiaia
TencentWin32.Trojan.Inject.Auto
Ad-AwareGen:Variant.Razy.805112
EmsisoftGen:Variant.Razy.805112 (B)
McAfee-GW-EditionPWS-FCRY!29B24AAFB947
SophosMal/Generic-S
Paloaltogeneric.ml
GDataGen:Variant.Razy.805112
AviraHEUR/AGEN.1235285
Antiy-AVLTrojan/MSIL.Kryptik
ZoneAlarmHEUR:Trojan-Spy.MSIL.Stealer.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.805112
MAXmalware (ai score=86)
MalwarebytesSpyware.RedLineStealer
APEXMalicious
RisingMalware.Obfus/MSIL@AI.94 (RDM.MSIL:ePmM4JS4YLP7C1yYCuv1gQ)
YandexTrojan.DR.Agent!F63E1ctCv9Q
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Kryptik.YVA!tr
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Razy.805112?

Razy.805112 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment