Malware

Should I remove “Razy.542800”?

Malware Removal

The Razy.542800 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.542800 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (23 unique times)
  • Starts servers listening on 0.0.0.0:3885
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Enumerates services, possibly for anti-virtualization
  • Executed a process and injected code into it, probably while unpacking
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • A possible cryptomining command was executed
  • Makes SMTP requests, possibly sending spam or exfiltrating data.
  • Attempts to interact with an Alternate Data Stream (ADS)

Related domains:

microsoft-com.mail.protection.outlook.com
181.86.68.138.dnsbl.sorbs.net
181.86.68.138.bl.spamcop.net
181.86.68.138.zen.spamhaus.org
181.86.68.138.sbl-xbl.spamhaus.org
181.86.68.138.cbl.abuseat.org
www.google.fr
www.instagram.com
msr.pool.gntl.co.uk
travis-scott-secure.myshopify.com
mcr.aacrjournals.org
global.edge.bamgrid.com
dwgin-production-eu01-snipes.demandware.net
www.luisaviaroma.com
www.footlocker.it

How to determine Razy.542800?


File Info:

crc32: AD0BE189
md5: 5904ac721bad2fc0425111ca1819233b
name: 5904AC721BAD2FC0425111CA1819233B.mlw
sha1: 891f2ad65b02853afd8b4918962c82949b19eed2
sha256: 55fcd255acc713485fdeec4bcdb099be77c282028f1440cd4a6b881bcf126f81
sha512: d5dbb2191ee01b9f3fa1a8b88bb6262d38cd01fb27cd40c17af88e8fd602e0677ca46aabcdd543b03c80a857690560e95ec5a6477bded951d6f0b2307256076d
ssdeep: 6144:KbV6VCxCVuydypIozzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzz:A6807dyp
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Razy.542800 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.542800
FireEyeGeneric.mg.5904ac721bad2fc0
McAfeeBackDoor-FDRN!5904AC721BAD
CylanceUnsafe
SangforMalware
BitDefenderGen:Variant.Razy.542800
Cybereasonmalicious.21bad2
InvinceaML/PE-A
CyrenW32/Tofsee.Q.gen!Eldorado
SymantecTrojan.Ascesso!gm
APEXMalicious
AvastWin32:BackdoorX-gen [Trj]
ClamAVWin.Trojan.Tofsee-6840338-0
KasperskyHEUR:Trojan.Win32.Generic
Ad-AwareGen:Variant.Razy.542800
ComodoTrojWare.Win32.Invader.AX@805y9n
F-SecureBackdoor.BDS/Backdoor.Gen
DrWebTrojan.Siggen11.4306
McAfee-GW-EditionBehavesLike.Win32.Backdoor.vh
EmsisoftGen:Variant.Razy.542800 (B)
IkarusTrojan.Win32.Tofsee
JiangminTrojan.Generic.glstp
AviraBDS/Backdoor.Gen
MicrosoftBackdoor:Win32/Tofsee.T
ArcabitTrojan.Razy.D84850
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Backdoor.Tofsee.C
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.Tofsee.R284452
Acronissuspicious
VBA32BScope.Trojan.Invader
ALYacGen:Variant.Razy.542800
MAXmalware (ai score=85)
MalwarebytesBackdoor.Tofsee
ESET-NOD32a variant of Win32/Tofsee.AX
RisingBackdoor.Tofsee!8.1E9 (TFE:3:uk6Joq68HQM)
YandexTrojan.GenAsa!XvO1cEIyueE
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Tofsee.AX!tr
BitDefenderThetaGen:NN.ZexaF.34590.@tW@ayX01Hb
AVGWin32:BackdoorX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM20.1.3967.Malware.Gen

How to remove Razy.542800?

Razy.542800 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment