Malware

Razy.912218 (B) removal guide

Malware Removal

The Razy.912218 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.912218 (B) virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Unconventionial language used in binary resources: Greek
  • The binary likely contains encrypted or compressed data.
  • Checks for the presence of known windows from debuggers and forensic tools
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • The following process appear to have been packed with Themida: 83C3A90E8661FFF471B73A6D1183A0D2.mlw
  • Network activity detected but not expressed in API logs
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

How to determine Razy.912218 (B)?


File Info:

crc32: B20E5EC8
md5: 83c3a90e8661fff471b73a6d1183a0d2
name: 83C3A90E8661FFF471B73A6D1183A0D2.mlw
sha1: 782166755161958ba07efa54d2f54ad186bd22c8
sha256: 1778913fe94865396756b84bff8e6180de47c8371869e9582ca34d8355d439db
sha512: 5c4fd4bf9ed8614ab5b557ba258eec71104aacf21fe98811fe23cf56a9999831622f19cd21811dda273aa01eba2638e9d69cabaef507902e9d624ec70793fea6
ssdeep: 98304:Ka31q5bNZBrck3HHCs7ix8+6dRu7j2MHe:Ka31qJNZBrFXHRet6dRuX2j
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

InternalName: sojbmoemonu.uhe
ProductVersion: 8.19.590.38
Copyright: Copyrighz (C) 2021, fudkagata
Translation: 0x0129 0x0167

Razy.912218 (B) also known as:

Elasticmalicious (high confidence)
McAfeeArtemis!83C3A90E8661
CylanceUnsafe
SangforTrojan.Win32.Save.a
Cybereasonmalicious.551619
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Razy.912218
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanGen:Variant.Razy.912218
Ad-AwareGen:Variant.Razy.912218
BitDefenderThetaGen:NN.ZexaE.34142.@N2@aee2IkjO
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.83c3a90e8661fff4
EmsisoftGen:Variant.Razy.912218 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
eGambitPE.Heur.InvalidSig
KingsoftWin32.Heur.KVMH008.a.(kcloud)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GridinsoftTrojan.Heur!.012124B1
GDataGen:Variant.Razy.912218
VBA32BScope.TrojanPSW.MSIL.Reline
MAXmalware (ai score=82)
MalwarebytesTrojan.MalPack.GS
RisingTrojan.Generic@ML.90 (RDML:nrq4jWTcBYhSnrCI6y8TtA)
YandexTrojan.PWS.Reline!iDXTBJL4B38
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Razy.912218 (B)?

Razy.912218 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment