Malware

What is “Razy.225789”?

Malware Removal

The Razy.225789 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.225789 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Starts servers listening on 127.0.0.1:0
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz
whatismyipaddress.com

How to determine Razy.225789?


File Info:

crc32: 2BA13301
md5: 2bf54a7df6ff368e75685bb19406473a
name: 2BF54A7DF6FF368E75685BB19406473A.mlw
sha1: af01eec64a5a0ff738de8cb3a2cbe3d7d1c75f8d
sha256: 265cb47cf80dc2641ce900dc72b5e6d08c9e7b90fb8946e9d56b7c9317b56f2c
sha512: 210338adf483bc0e98562e8ed81fbc171013de10a8dee2ecf565cf6aa81e3135fa490032dd4a1dcb23f756710de8572fc1b36be77161f68599309dbf7ad8090a
ssdeep: 12288:zHrR3mzLIJGU1z1sHNYcLD44NMOla9FlgHRYhYQNs4INIKVP7RwSFJP6ZwICcaT:FsLIXmfLtr8/6HRYg4IN/Pd5JSZscap
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: erterteygh
Assembly Version: 15.1578.1.441
InternalName: cfdsgferd.exe
FileVersion: 15.1578.1.441
CompanyName: ITT Corporation
Comments: Comments reserved for later usage...
ProductName: erterteygh
ProductVersion: 15.1578.1.441
FileDescription: iZotope usage metrics library
OriginalFilename: erterteygh.js
Translation: 0x0000 0x04b0

Razy.225789 also known as:

K7AntiVirusTrojan ( 0051904b1 )
LionicTrojan.MSIL.Generic.m!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader25.35988
ALYacGen:Variant.Razy.225789
MalwarebytesMachineLearning/Anomalous.97%
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaBackdoor:MSIL/Injector.d1d63c97
K7GWTrojan ( 0051904b1 )
Cybereasonmalicious.df6ff3
ESET-NOD32a variant of MSIL/Injector.TBE
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyHEUR:Backdoor.MSIL.Generic
BitDefenderGen:Variant.Razy.225789
NANO-AntivirusTrojan.Win32.Mlw.evlmxy
MicroWorld-eScanGen:Variant.Razy.225789
TencentWin32.Trojan.Inject.Auto
Ad-AwareGen:Variant.Razy.225789
BitDefenderThetaGen:NN.ZemsilF.34236.2m0@amdWYsc
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.2bf54a7df6ff368e
EmsisoftGen:Variant.Razy.225789 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1127559
eGambitUnsafe.AI_Score_62%
Antiy-AVLTrojan/Generic.ASMalwS.22CDA2F
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojanSpy:MSIL/Golroted.B
GDataGen:Variant.Razy.225789
AhnLab-V3Trojan/Win32.Bladabindi.R210647
McAfeePacked-SR!2BF54A7DF6FF
MAXmalware (ai score=100)
PandaTrj/GdSda.A
YandexTrojan.Injector!K5sGWK+heNo
IkarusTrojan.MSIL.Injector
FortinetMSIL/Injector.TCA!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Razy.225789?

Razy.225789 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment