Malware

What is “Razy.230553”?

Malware Removal

The Razy.230553 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.230553 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Expresses interest in specific running processes
  • A process created a hidden window
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Detects Sandboxie through the presence of a library
  • Code injection with CreateRemoteThread in a remote process
  • Sniffs keystrokes
  • Executed a process and injected code into it, probably while unpacking
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Likely virus infection of existing system binary
  • Checks for the presence of known devices from debuggers and forensic tools
  • Creates a copy of itself
  • Attempts to create or modify system certificates
  • Creates known SpyNet mutexes and/or registry changes.
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.yoursite.com
yoursite.com
babeu.ddns.net

How to determine Razy.230553?


File Info:

crc32: 19C50A66
md5: cb7611500845adc422a73c9be2515d54
name: CB7611500845ADC422A73C9BE2515D54.mlw
sha1: 39a21c897b3ac27ed7b664f2c0c79570737f8d1a
sha256: f20b6c3638dc864b427768f5f43af1f29b672934a2879b35d657007b78473bde
sha512: c9c3b7aaf0ffb90fa7115053800162f5ff584363acab0ab69f728efc9476928b7189629fe3c42221ce86a3df807f563dc07d407ecdc574589a0b1a7fd87d1146
ssdeep: 24576:5TbU7z5A9+KUczgwHhPXL2hO6r3IT12IBMkT54UM6/FrzO16IvC:5TctAdFvihr0T1fMkT54ULVzBIvC
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2005
Assembly Version: 84.74.82.62
InternalName: NETFLIX GENERATOR.EXE
FileVersion: 67.74.63.43
Comments: WindowsApplication37
ProductName: WindowsApplication37
ProductVersion: 67.74.63.43
FileDescription: WindowsApplication37
OriginalFilename: NETFLIX GENERATOR.EXE

Razy.230553 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.230553
FireEyeGeneric.mg.cb7611500845adc4
McAfeeArtemis!CB7611500845
MalwarebytesMachineLearning/Anomalous.100%
ZillyaTrojan.Blocker.Win32.38653
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004da4af1 )
BitDefenderGen:Variant.Razy.230553
K7GWTrojan ( 004da4af1 )
Cybereasonmalicious.00845a
BitDefenderThetaGen:NN.ZemsilF.34590.ln0@a8fJZke
CyrenW32/MSIL_Kryptik.DET.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 85)
KasperskyTrojan-Ransom.Win32.Blocker.kbyp
NANO-AntivirusTrojan.Win32.Blocker.epveai
TencentWin32.Trojan.Blocker.Taew
Ad-AwareGen:Variant.Razy.230553
SophosML/PE-A + Troj/MSIL-GIH
ComodoTrojWare.MSIL.Injector.MJL@7e5w7d
F-SecureHeuristic.HEUR/AGEN.1109456
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftGen:Variant.Razy.230553 (B)
IkarusTrojan.MSIL.Injector
AviraHEUR/AGEN.1109456
Antiy-AVLTrojan[Ransom]/Win32.Blocker
ArcabitTrojan.Razy.D38499
ZoneAlarmTrojan-Ransom.Win32.Blocker.kbyp
GDataGen:Variant.Razy.230553
VBA32CIL.StupidPInvoker-2.Heur
ALYacGen:Variant.Razy.230553
MAXmalware (ai score=83)
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Injector.NIK
YandexTrojan.Blocker!LtwI69z0v3g
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetMSIL/Injector.GIH!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Razy.230553?

Razy.230553 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment