Malware

Razy.811912 removal guide

Malware Removal

The Razy.811912 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.811912 virus can do?

  • Executable code extraction
  • Enumerates user accounts on the system
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Modifies boot configuration settings
  • Exhibits behavior characteristic of Cerber ransomware
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Uses suspicious command line tools or Windows utilities

How to determine Razy.811912?


File Info:

crc32: 01C8CA74
md5: ad0648e35f26894fdde1f171e75f4eb5
name: AD0648E35F26894FDDE1F171E75F4EB5.mlw
sha1: 815a69393bc0d1618a1ca473603d3dd75fcb711e
sha256: 92a0b6c046b2585ea890b68a63c08269b7bc4c2994dcacbdd71497d3f2008775
sha512: 26cea0e6e979a3275c12baac065ca510e2379dc41a1c6660a9d2dfbd27c992da784b74b281b8a00fcdebb3c79e5694a7332413f8af8887b8e1fdad90da89834b
ssdeep: 3072:ztuRdar6ftfDsZQco6wRGgVUe/m2Hk44vOSJLpesFztleG6CUr7hLLyy3qpdU5/:ztuzPsZxK4lT2E44vPVltleGdqLLydp
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Tecumseh
InternalName: bruised
FileVersion: 10.10.1508.0
CompanyName: Tecumseh
ProductName: bruised drinkings
ProductVersion: 10.10.1508.0
FileDescription: bruised intine
OriginalFilename: bruised.exe
Translation: 0x0409 0x04b0

Razy.811912 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.811912
ALYacGen:Variant.Razy.811912
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/starter.ali1000118
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.35f268
SymantecRansom.Cerber!gm
ESET-NOD32a variant of Generik.IXCCHEI
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.811912
NANO-AntivirusTrojan.Win32.Crypted.evczeb
TencentWin32.Trojan.Generic.Lmkk
Ad-AwareGen:Variant.Razy.811912
SophosML/PE-A + Mal/EncPk-ZC
ComodoMalCrypt.Indus!@1qrzi1
BitDefenderThetaGen:NN.ZexaF.34628.kq0@aidcQzbi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionRansomware-GIX!AD0648E35F26
FireEyeGeneric.mg.ad0648e35f26894f
EmsisoftGen:Variant.Razy.811912 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.bqtnq
AviraHEUR/AGEN.1105972
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/Cerber.A
GDataGen:Variant.Razy.811912
AhnLab-V3Malware/Win32.Generic.C2368081
Acronissuspicious
McAfeeRansomware-GIX!AD0648E35F26
MAXmalware (ai score=100)
VBA32TrojanRansom.Cerber
PandaTrj/GdSda.A
RisingRansom.Cerber!8.3058 (CLOUD)
YandexTrojan.GenAsa!SMdRII4tB8M
IkarusTrojan.SuspectCRC
FortinetW32/Generic!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.f7e

How to remove Razy.811912?

Razy.811912 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment