Malware

Razy.682012 removal guide

Malware Removal

The Razy.682012 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.682012 virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Razy.682012?


File Info:

name: DCBF7F8894940A7B854A.mlw
path: /opt/CAPEv2/storage/binaries/47eda08f8ca5aabcd58bfe7e80df786509cfad40642bb475a96e2052c3b6653b
crc32: FE0DDA59
md5: dcbf7f8894940a7b854ab66980df671c
sha1: a4c9d5ca1b0c51cdff929c1f3151a23468ea2b16
sha256: 47eda08f8ca5aabcd58bfe7e80df786509cfad40642bb475a96e2052c3b6653b
sha512: bf12edcc1231e756a63d55b7c7d2a46bc7e981663a3c75c51944b2d27238d4caf4f7367da1aad7632639bc6377d8a47553db9716c17872ac97b094a2c123189b
ssdeep: 1536:FlO/dkWR8BksMo53Ay+g2GbfEzauCSSQNsLeUP3HWquKz6mns9OAWeEVV+:S/dlHE2GbfmaWnulns93WeEVA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T136C352609EF01561F2B58B3D44F3534153363D02AF239B2E1AE4BE683DE36989E45B1B
sha3_384: d633b3be4a32c038437b75b8d6cea45ab33377cd319604a12cc1a10bfd659bcbc36d85e6359fb3f95100fefc48fe1787
ep_bytes: ff250020400000000000000000000000
timestamp: 2020-05-31 12:00:44

Version Info:

ProductName: Microsoft® Windows® Operating System
FileDescription: Microsoft Malware Protection Command Line Utility
CompanyName: Microsoft Corporation
LegalCopyright: © Microsoft Corporation. All rights reserved.
LegalTrademarks: bc2a1911 43c9 4994 bb3b 3ad7020dc40b
Comments: 0f473055 12e4 4585 b62e c89fcdbd3225
FileVersion: 4.18.1807.18075
ProductVersion: 4.18.1807.18075
Guid: b53f4a19-9388-401a-ba8b-c49a6c6116d3
Translation: 0x0000 0x04e4

Razy.682012 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.PackedNET.314
MicroWorld-eScanGen:Variant.Razy.682012
FireEyeGeneric.mg.dcbf7f8894940a7b
McAfeeGenericRXKX-XS!DCBF7F889494
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 00567e021 )
AlibabaBackdoor:MSIL/Crysan.26bd83ae
K7GWTrojan ( 00567e021 )
Cybereasonmalicious.894940
ArcabitTrojan.Razy.DA681C
BitDefenderThetaGen:NN.ZemsilF.34294.hm0@a4SwFPni
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/GenKryptik.ELYO
Paloaltogeneric.ml
KasperskyHEUR:Backdoor.MSIL.Crysan.gen
BitDefenderGen:Variant.Razy.682012
NANO-AntivirusTrojan.Win32.Crysan.hofyvr
AvastWin32:RATX-gen [Trj]
TencentMsil.Backdoor.Crysan.Wvbb
Ad-AwareGen:Variant.Razy.682012
SophosMal/Generic-S
McAfee-GW-EditionGenericRXKX-XS!DCBF7F889494
EmsisoftGen:Variant.Razy.682012 (B)
IkarusTrojan.MSIL.Agent
JiangminBackdoor.MSIL.dayy
WebrootW32.Trojan.Gen
AviraTR/Crypt.XDR.Gen
Antiy-AVLTrojan/Generic.ASMalwS.30873A2
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Razy.682012
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.682012
MAXmalware (ai score=83)
MalwarebytesBackdoor.AsyncRAT.Generic
APEXMalicious
SentinelOneStatic AI – Malicious PE
FortinetMSIL/GenKryptik.ELNC!tr
AVGWin32:RATX-gen [Trj]
PandaTrj/GdSda.A

How to remove Razy.682012?

Razy.682012 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment