Malware

Razy.757777 (file analysis)

Malware Removal

The Razy.757777 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.757777 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Mimics the system’s user agent string for its own requests
  • Drops a binary and executes it
  • Deletes its original binary from disk
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Razy.757777?


File Info:

crc32: C078983D
md5: 86c6bd505b042bdc212472f56f32f3d0
name: 86C6BD505B042BDC212472F56F32F3D0.mlw
sha1: 433125dee8a119fcf363f31299ecbb88d6e6116e
sha256: 01c9e34af266f31530a6a97fed2e852766e8f956f06fa9434d7c75017f25cc42
sha512: 09d7b693b81fbd42483c64acfff522cfa19db372112d918264e99aefa8e489d392d341808f0c7a40e704d342fecfc7bc4a4cbadb7e363029eca8ad52b9b7b7ba
ssdeep: 6144:Y53MAu+OhjbC2JAsK/f1H0A0v/BZ0vDDoJFHk5kkgrVyv:YmAuthjGwK/f1H0AFoBOCV
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName: CALCDRIV
FileVersion: 1.0.001
CompanyName:
LegalTrademarks:
ProductName: CALCDRIV
ProductVersion: 1.0.001
FileDescription: CALCDRIV MFC Application
OriginalFilename: CALCDRIV.EXE
Translation: 0x0409 0x04e4

Razy.757777 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.757777
FireEyeGeneric.mg.86c6bd505b042bdc
ALYacGen:Variant.Razy.757777
SangforMalware
BitDefenderGen:Variant.Razy.757777
TrendMicroTrojanSpy.Win32.EMOTET.SMB.hp
CyrenW32/Casur.D.gen!Eldorado
SymantecPacked.Generic.554
APEXMalicious
AvastWin32:BankerX-gen [Trj]
ClamAVWin.Dropper.Emotet-7351589-0
KasperskyHEUR:Trojan-Banker.Win32.Emotet.vho
RisingTrojan.Emotet!1.BE40 (CLASSIC)
Ad-AwareGen:Variant.Razy.757777
TACHYONBanker/W32.Emotet.548870
EmsisoftTrojan.Emotet (A)
InvinceaML/PE-A
McAfee-GW-EditionBehavesLike.Win32.BrowseFox.hm
IkarusTrojan-Banker.Emotet
WebrootW32.Trojan.Gen
MicrosoftTrojan:Win32/Emotet.BX!MTB
GridinsoftTrojan.Win32.Agent.dd!n
ArcabitTrojan.Razy.DB9011
SUPERAntiSpywareTrojan.Agent/Gen-Emotet
ZoneAlarmHEUR:Trojan-Banker.Win32.Emotet.vho
GDataGen:Variant.Razy.757777
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Emotet.R299357
Acronissuspicious
McAfeeGenericRXMP-MI!86C6BD505B04
MAXmalware (ai score=86)
MalwarebytesTrojan.Emotet
ESET-NOD32a variant of Win32/Kryptik.GXNJ
TrendMicro-HouseCallTrojanSpy.Win32.EMOTET.SMB.hp
YandexTrojan.GenAsa!zZBsCK+YA0s
SentinelOneStatic AI – Suspicious PE
FortinetW32/Kryptik.EEDP!tr
BitDefenderThetaGen:NN.Zextet.34634.Hy1@aKpBLZei
AVGWin32:BankerX-gen [Trj]

How to remove Razy.757777?

Razy.757777 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment