Malware

How to remove “Razy.821962 (B)”?

Malware Removal

The Razy.821962 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.821962 (B) virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Looks up the external IP address
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to delete volume shadow copies
  • Exhibits behavior characteristic of Alphacrypt/Teslacrypt ransomware
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Attempts to identify installed AV products by registry key
  • Creates a copy of itself
  • Creates a known TeslaCrypt/AlphaCrypt ransomware decryption instruction / key file.
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

myexternalip.com
ocsp.pki.goog
kochstudiomaashof.de
testadiseno.com
diskeeper-asia.com
gjesdalbrass.no
garrityasphalt.com
www.garrityasphalt.com
grassitup.com
crl.pki.goog
crls.pki.goog
www.godaddy.com

How to determine Razy.821962 (B)?


File Info:

crc32: 8717FD5F
md5: 57c961ef6bf446447cc67f9a6ebf9371
name: 57C961EF6BF446447CC67F9A6EBF9371.mlw
sha1: 491867fb9b25c2170390b0c1e076561e5de7703e
sha256: 5d3aae382c5e76531b67eb1216454da32380ed0b209d1d16f565481f2bd9f198
sha512: f9300b502d3052b1ae1036fa7c3b106e9936d9f0965c9661e80ba82c3d91c8e16bd9b6c79199488f046a1d8404cb34555d83f1e53b2846d26989a2b47a29baeb
ssdeep: 6144:aBcpeg6dPhFapmHZeTFwyhQaONSkGwILKNY4Zc/o2YdtRC+lJcc:kseg6dp3ZeWyhQaONSkG7GNbcAPTRVl
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Inspiring (C) 2018
InternalName: Imminence
FileDescription: Encamped
OriginalFilename: Machinations.exe
CompanyName: TechniSat Digital, S.A.

Razy.821962 (B) also known as:

K7AntiVirusRiskware ( 0040eff71 )
LionicTrojan.Win32.Yakes.4!c
Elasticmalicious (high confidence)
DrWebTrojan.AVKill.63843
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.821962
CylanceUnsafe
ZillyaDownloader.Adload.Win32.29411
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Tescrypt.21bf7618
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.f6bf44
BaiduWin32.Trojan.Filecoder.k
SymantecRansom.TeslaCrypt!g1
ESET-NOD32Win32/Filecoder.TeslaCrypt.I
APEXMalicious
AvastWin32:TeslaCrypt-K [Trj]
ClamAVWin.Ransomware.TeslaCrypt-7135496-1
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.821962
NANO-AntivirusTrojan.Win32.AVKill.dzdbny
ViRobotTrojan.Win32.TeslaCrypt.Gen.A
MicroWorld-eScanGen:Variant.Razy.821962
TencentMalware.Win32.Gencirc.10c4d1b6
Ad-AwareGen:Variant.Razy.821962
SophosML/PE-A + Troj/Ransom-BTZ
ComodoMalware@#34pijbfdf4od8
BitDefenderThetaGen:NN.ZexaF.34790.vy0@aOPekWgG
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CRYPTESLA.SMJ4
McAfee-GW-EditionGenericR-FIJ!57C961EF6BF4
FireEyeGeneric.mg.57c961ef6bf44644
EmsisoftGen:Variant.Razy.821962 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Yakes.dzt
AviraTR/Dropper.Gen8
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.160686F
MicrosoftRansom:Win32/Tescrypt
ArcabitTrojan.Razy.DC8ACA
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
GDataGen:Variant.Razy.821962
AhnLab-V3Trojan/Win32.Teslacrypt.R292508
McAfeeGenericR-FIJ!57C961EF6BF4
MAXmalware (ai score=81)
VBA32Trojan.Yakes
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_CRYPTESLA.SMJ4
RisingTrojan.Agent!1.A322 (CLASSIC)
YandexTrojan.GenAsa!5SCgDYEhCms
IkarusTrojan.Win32.Filecoder
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.COBY!tr
AVGWin32:TeslaCrypt-K [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Tescrypt.HgIASWgA

How to remove Razy.821962 (B)?

Razy.821962 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment