Malware

Should I remove “Razy.665116”?

Malware Removal

The Razy.665116 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.665116 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Razy.665116?


File Info:

name: 875C3194F8A007CEEA8D.mlw
path: /opt/CAPEv2/storage/binaries/0137ca9c257fe3ba300f305037a39554220466647bfab223f6a2be46b1054956
crc32: 3FCA32BE
md5: 875c3194f8a007ceea8da94e3db90472
sha1: b40d728a97f3fd45ee67fafcb5b5304ac62f95d5
sha256: 0137ca9c257fe3ba300f305037a39554220466647bfab223f6a2be46b1054956
sha512: ebdf6514e64273a748047ed7f053a1d16f662c2057dc011d4fa5d43226bf1c2f9dc31ef3ada7244f15b5e6204190e79d4fd1162a284070bcd88a887db660d922
ssdeep: 12288:1qlQftRU9tRUeKpiKSe3XtRUW6N6Mt+8S:1qjeeKpoDMl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C5F43B926256D598CED6CAB03585505CE72ECD313E739A20262F7F18FF72D9C788422B
sha3_384: 257b2a6c987c5de355c3f6ff17c1321f9ee3c2572b9f9426c0a9efd350129d32bb6b4a8c668d49589b8ba352befb9cdd
ep_bytes: ff250020400000000000000000000000
timestamp: 2016-10-12 17:20:18

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName: Skidrow
FileDescription: nowyprojekt32
FileVersion: 1.0.0.0
InternalName: symulatorfarmy2017.exe
LegalCopyright: Copyright © Acer 2015
LegalTrademarks:
OriginalFilename: symulatorfarmy2017.exe
ProductName: nowyprojekt32
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Razy.665116 also known as:

BkavW32.AIDetectNet.01
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Surveyer.32
MicroWorld-eScanGen:Variant.Razy.665116
FireEyeGeneric.mg.875c3194f8a007ce
CAT-QuickHealTrojan.WacatacFC.S18288353
ALYacGen:Variant.Razy.665116
CylanceUnsafe
SangforTrojan.Win32.Surveyer.8
K7AntiVirusTrojan ( 700000121 )
K7GWTrojan ( 700000121 )
Cybereasonmalicious.4f8a00
BitDefenderThetaGen:NN.ZemsilF.34606.Sm0@ayj2g3p
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Surveyer.EN
APEXMalicious
BitDefenderGen:Variant.Razy.665116
NANO-AntivirusTrojan.Win32.Surveyer.eocakb
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Razy.665116
SophosMal/Generic-S
McAfee-GW-EditionArtemis!Trojan
EmsisoftGen:Variant.Razy.665116 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Razy.665116
AviraHEUR/AGEN.1223089
KingsoftWin32.Troj.Generic_a.a.(kcloud)
CynetMalicious (score: 99)
McAfeeArtemis!875C3194F8A0
MAXmalware (ai score=88)
MalwarebytesTrojan.Surveyer.MSIL
YandexTrojan.Surveyer!1NlVJ+UxSzk
IkarusTrojan.MSIL.Surveyer
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Generic.AP.CFB3CD4!tr
AVGWin32:Malware-gen
PandaTrj/GdSda.A

How to remove Razy.665116?

Razy.665116 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment