Malware

Razy.612195 malicious file

Malware Removal

The Razy.612195 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.612195 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Razy.612195?


File Info:

name: 4BF7CC48DCE659739A54.mlw
path: /opt/CAPEv2/storage/binaries/462296e005839e95736ab8b0284325a30c21614585196ec4b8009ebdc08726eb
crc32: 297A8F21
md5: 4bf7cc48dce659739a5407d7f7061c3c
sha1: 9558e6e977c362939921556ee83c8ea1e977d0ae
sha256: 462296e005839e95736ab8b0284325a30c21614585196ec4b8009ebdc08726eb
sha512: 105edd26a2754206e827b31dbca9f6d55e2ca2b897ef52ca4d6f63e852d8645de115331730755995a74128f95bb45f14ce2985f51e5692ed14e11be17f454c7c
ssdeep: 3072:/bY96CjQdTNEAzsRaD0dMf8egs5i6fbXF0pLC0hFv3ypde4k:/FC8XEQRBiIXF0ZC0hFvyd1k
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1C3140D1965418CB9C46377BA809BC6AB6238BF4483331F0F6EAD0D35BB377816C95396
sha3_384: 250f1b5b0bd58f2c85be54fcf34e7383cadc36542cd0d4385a96c81b0f9ecefa380f199ffaf35487e2a2dc42f91ff48a
ep_bytes: 5589e583ec18c745f4ff000000c705b8
timestamp: 2021-11-28 11:01:14

Version Info:

0: [No Data]

Razy.612195 also known as:

McAfeeRDN/Generic.dx
CylanceUnsafe
BitDefenderThetaGen:NN.ZexaF.34084.m8Z@a4JkMnl
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002H06L521
KasperskyHEUR:Trojan.Win32.Agentb.gen
AlibabaTrojan:Win32/Generic.57edbe11
SophosMal/Generic-R
ZillyaTrojan.Convagent.Win32.7944
McAfee-GW-EditionRDN/Generic.dx
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GridinsoftRansom.Win32.Sabsik.sa
GDataWin32.Application.PUPStudio.6WW6RB
ALYacGen:Variant.Razy.612195
TencentWin32.Trojan.Agentb.Phqt
FortinetRiskware/Application
AVGWin32:Malware-gen
AvastWin32:Malware-gen

How to remove Razy.612195?

Razy.612195 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment