Malware

What is “Razy.691212”?

Malware Removal

The Razy.691212 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.691212 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time

How to determine Razy.691212?


File Info:

name: 33F4377C1979C79A46DB.mlw
path: /opt/CAPEv2/storage/binaries/327b0c646e9b8f54fab3e0e1a34e29b72dc1b6050824128fddc6f0dee06a302c
crc32: EB0BE191
md5: 33f4377c1979c79a46dbcc7adcc4de25
sha1: 2a6b4bd8196f7847f214ee70903a44703b86d065
sha256: 327b0c646e9b8f54fab3e0e1a34e29b72dc1b6050824128fddc6f0dee06a302c
sha512: 9cbb2223f67ffd7d5f57ab025de599fce3829effadda7fb0964ec3e106658d00d1bd0c1c64458f5ffc8f56ce73de3de0edd425ecb5291ea7f2bbee93fad34746
ssdeep: 6144:lak0uYjdtTJTnN8zlp3JbaiHdyrlgAbuss3atDLq+uay0MVG/9gZn06V0f8i:laZvVN8T3Jmi9KgAbrutHQKZ0gF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1007413065EC36D7DCAE843B13C3F1A2B0861C546E2655ADBB84C313EAB1EFD845B24D6
sha3_384: 8e33d3d164e356fed49db52c79d9f26bb4238e584ca52744df9d86f2ea2d2a81a6b3168af6cf9da01f9a9a522ff7dd85
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-01-25 07:51:33

Version Info:

Translation: 0x0000 0x04b0
Comments: Google Updates
CompanyName: Google Inc.
FileDescription: updates
FileVersion: 1.0.0.0
InternalName: crypted.exe
LegalCopyright: Google
OriginalFilename: crypted.exe
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Razy.691212 also known as:

LionicTrojan.Win32.Generic.loKa
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.691212
FireEyeGeneric.mg.33f4377c1979c79a
McAfeeArtemis!33F4377C1979
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004ca3531 )
AlibabaTrojan:MSIL/Injector.a59fabf7
K7GWTrojan ( 004ca3531 )
Cybereasonmalicious.c1979c
BitDefenderThetaGen:NN.ZemsilF.34182.wm0@aunhjdd
CyrenW32/Trojan.EVOZ-0181
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.CDQ
TrendMicro-HouseCallBKDR_BLADABINDI.SMSH
Paloaltogeneric.ml
ClamAVWin.Packed.Generic-7372636-0
KasperskyHEUR:Trojan.MSIL.Generic
BitDefenderGen:Variant.Razy.691212
NANO-AntivirusTrojan.Win32.CDQ.dbjagq
AvastWin32:KeyloggerX-gen [Trj]
TencentMsil.Trojan.Generic.Llrg
EmsisoftGen:Variant.Razy.691212 (B)
TrendMicroBKDR_BLADABINDI.SMSH
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
SentinelOneStatic AI – Malicious PE
SophosML/PE-A + Mal/Kryptik-S
APEXMalicious
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.351C7E6
GridinsoftRansom.Win32.Bladabindi.sa
MicrosoftTrojan:Win32/Woreflint.A!cl
ZoneAlarmHEUR:Trojan.MSIL.Generic
GDataGen:Variant.Razy.691212
CynetMalicious (score: 99)
AhnLab-V3Win-Trojan/MSILKrypt02.Exp
ALYacGen:Variant.Razy.691212
MAXmalware (ai score=83)
MalwarebytesMachineLearning/Anomalous.100%
RisingMalware.Obfus/MSIL@AI.96 (RDM.MSIL:gTA7TJj32DG1WSKxVMeLhA)
IkarusVirus.ILCrypt
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Dropper.ESN!tr
AVGWin32:KeyloggerX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Razy.691212?

Razy.691212 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment