Malware

Should I remove “Razy.705124”?

Malware Removal

The Razy.705124 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.705124 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Turkish
  • The binary likely contains encrypted or compressed data.
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
xred.mooo.com
freedns.afraid.org
ocsp.pki.goog

How to determine Razy.705124?


File Info:

crc32: 2252269B
md5: 57c1ea4d5a28a4ddeed9cb00f6b81334
name: 57C1EA4D5A28A4DDEED9CB00F6B81334.mlw
sha1: cc96fe4d57dfc2788e714b0c921f24b7700d5f48
sha256: 3c496f04c7646b833a3f0af2b827bce859f85969d83ab5bfb52adea9c2237bc4
sha512: 8410234f7d455d59c9a52b90cc95a420c82b65876b72d02b001d2ab8b5e3b1b9eb538dd6fa1bc430a172b7e7ac75464ed50370d0a1ce5aa5a3af06555157459a
ssdeep: 24576:p1Z4RscUgrdv0qTrO8LiAclb3a0Af7EecLc7Il+U/2p62brk3bltd:XZ7cF0qa8L2MzEegkIl+lprHOrd
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName:
FileVersion: 1.0.0.4
CompanyName: Synaptics
LegalTrademarks:
Comments:
ProductName: Synaptics Pointing Device Driver
ProductVersion: 1.0.0.0
FileDescription: Synaptics Pointing Device Driver
OriginalFilename:
Translation: 0x041f 0x04e6

Razy.705124 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005239691 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.705124
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0057543a1 )
Cybereasonmalicious.d5a28a
CyrenW32/Trojan.JCNQ-3293
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.NoobyProtect.G suspicious
APEXMalicious
AvastWin32:Malware-gen
KasperskyBackdoor.Win32.Farfli.bwar
BitDefenderGen:Variant.Razy.705124
MicroWorld-eScanGen:Variant.Razy.705124
Ad-AwareGen:Variant.Razy.705124
SophosMal/Generic-S
ComodoTrojWare.Win32.Amtar.KNB@4wlm66
BitDefenderThetaGen:NN.ZexaF.34770.Ev0@aaICcniH
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
FireEyeGeneric.mg.57c1ea4d5a28a4dd
EmsisoftGen:Variant.Razy.705124 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1135156
eGambitUnsafe.AI_Score_100%
MicrosoftProgram:Win32/Wacapew.C!ml
GridinsoftTrojan.Heur!.03010121
ArcabitTrojan.Razy.DAC264
GDataWin32.Application.PUPStudio.A
AhnLab-V3Malware/Win.Generic.C4537607
Acronissuspicious
McAfeeArtemis!57C1EA4D5A28
MAXmalware (ai score=82)
MalwarebytesLamer.Virus.FileInfector.DDS
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R005H09FR21
RisingTrojan.Generic@ML.100 (RDML:j7l3fOox00+GKQvJlU0Zgg)
YandexTrojan.GenAsa!oSg9Hu4ydds
IkarusPUA.NoobyProtect
MaxSecureDropper.Dinwod.frindll
FortinetRiskware/Farfli
AVGWin32:Malware-gen
Qihoo-360Win32/Trojan.Generic.HgIASXUA

How to remove Razy.705124?

Razy.705124 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment