Malware

What is “Razy.813082”?

Malware Removal

The Razy.813082 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.813082 virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

b964abcdb332e12a.xyz

How to determine Razy.813082?


File Info:

crc32: 0DA85F44
md5: b7234e4a9aaaacefa890535f8117c8fc
name: B7234E4A9AAAACEFA890535F8117C8FC.mlw
sha1: 24c4321111ff004105c14e29662682f16900de29
sha256: a8fefe8e1f92a30d1cdd4e2e2afaacf08a02c8961f496ee16e89062417ec5f28
sha512: 8590be6433943bec0867a18247e25d9821d39db1d06c6957d3895558eb5568dddff0b97acda222f0a16701c50de43d8ad667d6717add6900ec941e71ca28e513
ssdeep: 98304:4u181qMJuVwd7Qld5ElgJQaQsPRT2KJLNx6DfgteKbeOJ:n294g7QxElWQaQyRTXy4vJ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 1998-2015 Kingsoft Corporation
InternalName: KInstallTool
FileVersion: 2015,09,24,14384
CompanyName: Kingsoft Corporation
ProductName: Kingsoft Internet Security
ProductVersion: 9,3,252534,14384
FileDescription: Kingsoft Install Tool
OriginalFilename: KInstallTool.exe
Translation: 0x0000 0x04b0

Razy.813082 also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.813082
McAfeeGenericRXAA-AA!B7234E4A9AAA
MalwarebytesSpyware.PasswordStealer
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win64.Frank.5!c
SangforMalware
CrowdStrikewin/malicious_confidence_90% (D)
BitDefenderGen:Variant.Razy.813082
K7GWAdware ( 004f5c3c1 )
K7AntiVirusAdware ( 004f5c3c1 )
ArcabitTrojan.Razy.DC681A
CyrenW32/Trojan.WPCC-8673
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Rootkit.Win64.Frank.vho
AlibabaRootkit:Win32/Frank.e5155a44
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
Ad-AwareGen:Variant.Razy.813082
EmsisoftGen:Variant.Razy.813082 (B)
ComodoMalware@#1939z4hpprszs
DrWebTrojan.Siggen11.60294
TrendMicroTROJ_FRS.0NA103AT21
McAfee-GW-EditionArtemis!Trojan
FireEyeGen:Variant.Razy.813082
SophosMal/Generic-S
IkarusTrojan.Win32.Krypt
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/CryptInject!ml
ZoneAlarmHEUR:Rootkit.Win64.Frank.vho
GDataWin32.Trojan.Kryptik.6BE9OZ
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.RL_Generic.R361585
ALYacGen:Variant.Razy.813082
MAXmalware (ai score=82)
CylanceUnsafe
PandaTrj/CI.A
ESET-NOD32Win32/Mingloa.E
TrendMicro-HouseCallTROJ_FRS.0NA103AT21
SentinelOneStatic AI – Malicious PE
FortinetAdware/Frank
WebrootW32.Gen.BT
AVGWin32:Malware-gen
Cybereasonmalicious.a9aaaa
AvastWin32:Malware-gen
Qihoo-360Win32/Rootkit.Generic.HxMB7DgA

How to remove Razy.813082?

Razy.813082 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment