Malware

Razy.696012 removal guide

Malware Removal

The Razy.696012 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.696012 virus can do?

  • Network activity detected but not expressed in API logs

How to determine Razy.696012?


File Info:

crc32: CE99F573
md5: 180d90607a62e9df3794833479505f5a
name: 180D90607A62E9DF3794833479505F5A.mlw
sha1: a6998238745dbef4bd06a18d45e7d9cd4eacd08e
sha256: 341c4507635c2de3deb4a98b208b7e213bce42ae6fe3366705f1129feb08f5ad
sha512: a5da52e6e16d9cf3d08b8e4315305de74baada756d9483e72d3561d0813f4105071818fed801d822b94b859707ce3a36b5616938ba03d573d846ec7cb8b9bd11
ssdeep: 1536:xWHqdHrGMJMkcZ2erLsHWXXA73raOHWtw0/w7jFcMTt:x3r5erLsHWHA77aOHWe0YvFt
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 1996-2018 VideoLAN and VLC Author
Assembly Version: 3.0.3.0
InternalName: jp.exe
FileVersion: 3.0.3.0
CompanyName: VLC media player
LegalTrademarks: VLC media player, VideoLAN and x264 are registered trademarks from VideoLAN
Comments: VLC media player
ProductName: VLC media player
ProductVersion: 3.0.3.0
FileDescription: VLC media player
OriginalFilename: jp.exe

Razy.696012 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.696012
FireEyeGeneric.mg.180d90607a62e9df
McAfeeArtemis!180D90607A62
MalwarebytesTrojan.ClipBanker.MSIL
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0056a61a1 )
K7GWTrojan ( 0056a61a1 )
Cybereasonmalicious.07a62e
BitDefenderThetaGen:NN.ZemsilF.34590.fm0@aCEj5Ag
ESET-NOD32a variant of MSIL/ClipBanker.PP
APEXMalicious
KasperskyHEUR:Trojan-Banker.MSIL.ClipBanker.gen
BitDefenderGen:Variant.Razy.696012
RisingDropper.Generic!8.35E (TFE:C:jkJZaJXprpO)
Ad-AwareGen:Variant.Razy.696012
ZillyaTrojan.ClipBanker.Win32.4650
EmsisoftGen:Variant.Razy.696012 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Banker.MSIL.cdx
MaxSecureTrojan.Malware.73489558.susgen
AviraTR/Dropper.MSIL.aroxm
Antiy-AVLTrojan[Banker]/MSIL.ClipBanker
ArcabitTrojan.Razy.DA9ECC
AhnLab-V3Malware/Win32.RL_Generic.C4153635
ZoneAlarmHEUR:Trojan-Banker.MSIL.ClipBanker.gen
GDataGen:Variant.Razy.696012
CynetMalicious (score: 85)
VBA32TScope.Trojan.MSIL
ALYacGen:Variant.Razy.696012
YandexTrojan.ClipBanker!fbmMcX0ycjk
IkarusTrojan.MSIL.ClipBanker
eGambitUnsafe.AI_Score_99%
FortinetMSIL/ClipBanker.PP!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen

How to remove Razy.696012?

Razy.696012 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment