Malware

Razy.888331 removal tips

Malware Removal

The Razy.888331 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.888331 virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Unconventionial language used in binary resources: Malay (Brunei Darussalam)
  • Checks for the presence of known windows from debuggers and forensic tools
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Network activity detected but not expressed in API logs
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Razy.888331?


File Info:

crc32: 6CEC781D
md5: bb8e07a1ca72e3a4bef0ecfe09459de7
name: BB8E07A1CA72E3A4BEF0ECFE09459DE7.mlw
sha1: a325cb86c0b6db451b40982daf430c0a2f8490b8
sha256: 0c580c106cfd6055e480fb8405575c294729ee0abb0037f5f84e6ae33ad27b69
sha512: 85fa3fdde9dc0d44a08266356cdf9322d4b3dea7a77964d26aa8d6bece60634cc164e19d4c5ff6e532a60cb3d61fe23e1c270e1b50ea8ed9cd8365f1924cc4dd
ssdeep: 24576:20LOitu3oX6tSEfAlngKDmy/Hk3C6hlLJ298iE7kGEyE7uvYxl+Ltdk8XswB5oW:XrraolBo//omVcLmWlZ7t
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2014
Assembly Version: 2.1.9.0
InternalName: SidNameU.exe
FileVersion: 2.1.9.1
CompanyName:
LegalTrademarks:
Comments:
ProductName: InvoicesManager_ver2
ProductVersion: 2.1.9.1
FileDescription: InvoicesManager_ver2
OriginalFilename: SidNameU.exe

Razy.888331 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.888331
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (W)
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.6c0b6d
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenCBL.ANK
APEXMalicious
AvastWin32:DangerousSig [Trj]
KasperskyTrojan-PSW.MSIL.Reline.dhl
BitDefenderGen:Variant.Razy.888331
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanGen:Variant.Razy.888331
Ad-AwareGen:Variant.Razy.888331
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34790.0E1@aCe0oVeO
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.bb8e07a1ca72e3a4
EmsisoftGen:Variant.Razy.888331 (B)
SentinelOneStatic AI – Suspicious PE
MicrosoftTrojan:Win32/Sabsik.FL.A!ml
GridinsoftTrojan.Heur!.010100A1
ArcabitTrojan.Razy.DD8E0B
GDataGen:Variant.Razy.888331
McAfeeArtemis!BB8E07A1CA72
MAXmalware (ai score=86)
VBA32BScope.TrojanPSW.MSIL.ClipSteal
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002H07G521
IkarusTrojan.Win32.Generic
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGWin32:DangerousSig [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HxMBYBsB

How to remove Razy.888331?

Razy.888331 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment