Malware

Razy.122809 removal

Malware Removal

The Razy.122809 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.122809 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Drops a binary and executes it
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
sysupdate.cf

How to determine Razy.122809?


File Info:

crc32: 203516F4
md5: 4d9aad95ceee13ae875b779c073e08e8
name: 4D9AAD95CEEE13AE875B779C073E08E8.mlw
sha1: b9e908c923fd17b5ef5e73e19a3e32d5d40eca34
sha256: d03434e71653a8e3573d00ecf76462de6110c9c80c21c028d3b5d03e2a63e497
sha512: 246ad2af89236efa3b55dd92c190ef3dbc062410c5b5d0d9b5d181c2ffe5a7ac8ba8b20e588ca61a047bc0990359c37d68f35c821f17aeeccb63a9dde30a42eb
ssdeep: 768:FER+BEXqw3PH8ddddddddddNiSSSTrhSSOefQkLeCE6vQNa17r:FERcFwv0fQkZ
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: sysupdate.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: sysupdate.exe

Razy.122809 also known as:

K7AntiVirusRiskware ( 0040eff71 )
LionicTrojan.Win32.Blocker.j!c
DrWebTrojan.DownLoader23.44737
CynetMalicious (score: 99)
ALYacGen:Variant.Razy.122809
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.5ceee1
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.jwht
BitDefenderGen:Variant.Razy.122809
NANO-AntivirusTrojan.Win32.Zusy.eswiuw
MicroWorld-eScanGen:Variant.Razy.122809
TencentWin32.Trojan.Blocker.Pgdm
Ad-AwareGen:Variant.Razy.122809
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34126.bm0@a4gHoao
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.4d9aad95ceee13ae
EmsisoftGen:Variant.Razy.122809 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Blocker.ghh
AviraTR/Dropper.MSIL.pfwer
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftBackdoor:Win32/Bladabindi!ml
GDataGen:Variant.Razy.122809
McAfeeArtemis!4D9AAD95CEEE
MAXmalware (ai score=99)
PandaTrj/GdSda.A
YandexTrojan.DownLoader!/lf7iUMVMdI
IkarusTrojan.Dropper
FortinetW32/Blocker.JWHT!tr
AVGWin32:Malware-gen

How to remove Razy.122809?

Razy.122809 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment