Malware

Should I remove “Ser.Razy.11068”?

Malware Removal

The Ser.Razy.11068 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ser.Razy.11068 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Ser.Razy.11068?


File Info:

name: 8D6222E9B965860BD350.mlw
path: /opt/CAPEv2/storage/binaries/2b1247aa8600dd1a1f043d94a6f751ae1cc25e9fd5de19a2be612a4f66a7f424
crc32: E12F9C5F
md5: 8d6222e9b965860bd3508bce9c90cc32
sha1: c818fb95f6a20e711011e88c98a2bdc2294d3b90
sha256: 2b1247aa8600dd1a1f043d94a6f751ae1cc25e9fd5de19a2be612a4f66a7f424
sha512: 5b66f63ddebbe97e6814d0921e8afa63deee91e82d2e6eab963a330990e14831d74e99af7a7c947430aecda29f969f82c2ba9e18f5cbf0722caefa0ee6b23403
ssdeep: 6144:qROWRXD3aTe3fxh2/qeLfuYfeLzOy0ya:qRzx3aa3fx8/q0f6Gy0L
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13014BF1D318361B2C4B828FC435CB8B5B0FBFD5A3AD5BF315507AF10EE62489616D8A9
sha3_384: 569c663847e3664f3c526e8bb69aa5c86c71c21fb009aaa5235ff3d797eeebecf53d2af283c794bfb0e2c14bce6de711
ep_bytes: 837dd8007502eb5683fa6d7502eb4ff7
timestamp: 2008-02-20 23:04:54

Version Info:

CompanyName: ХУймДХСьОпЫШцюШХЫИЩЬАзгБхгц
FileDescription: яхЮЮяТьпЬЬвкзйхОптТДкОвСЕ
FileVersion: 14.71.63.7
InternalName: чихЦУшпЯУвЪИДипУщЬЗУнЧмТЕсгП
OriginalFilename: Jk7MPn.exe
ProductName: яЭзыпйИрзЮшихЬъЗяжРЧлдоДДэКЖ
ProductVersion: 14.71.63.7
Translation: 0x04b0 0x0417

Ser.Razy.11068 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ser.Razy.11068
FireEyeGeneric.mg.8d6222e9b965860b
McAfeePWS-Zbot.gen.aum
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.881621
SangforTrojan.Win32.Obitel.8
K7AntiVirusTrojan ( 001475fa1 )
AlibabaTrojanPSW:Win32/Kryptik.c6264647
K7GWTrojan ( 001475fa1 )
Cybereasonmalicious.9b9658
BitDefenderThetaAI:Packer.498EE9F31F
VirITTrojan.Win32.SHeur3.VJQ
CyrenW32/Qakbot.A.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Kryptik.EJT
APEXMalicious
Paloaltogeneric.ml
KasperskyPacked.Win32.Krap.gx
BitDefenderGen:Variant.Ser.Razy.11068
NANO-AntivirusTrojan.Win32.Krap.ebzwxu
AvastWin32:MalOb-IJ [Cryp]
TencentWin32.Packed.Krap.Ecuc
Ad-AwareGen:Variant.Ser.Razy.11068
EmsisoftGen:Variant.Ser.Razy.11068 (B)
ComodoMalCrypt.Indus!@1qrzi1
VIPRETrojan.Win32.Nedsym.f (v)
TrendMicroBKDR_QAKBOT.SMB
McAfee-GW-EditionPWS-Zbot.gen.aum
SophosMal/Generic-R + Mal/Qbot-B
IkarusPacker.Win32.Krap
GDataGen:Variant.Ser.Razy.11068
JiangminPacked.Krap.dilp
AviraTR/Dropper.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.18473FD
ZoneAlarmPacked.Win32.Krap.gx
MicrosoftPWS:Win32/Zbot.gen!R
CynetMalicious (score: 100)
Acronissuspicious
ALYacGen:Variant.Ser.Razy.11068
TrendMicro-HouseCallBKDR_QAKBOT.SMB
RisingDropper.Obitel!8.1F55 (CLOUD)
YandexTrojan.Kryptik!8BM/F57wOiQ
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.EJT!tr
AVGWin32:MalOb-IJ [Cryp]
PandaTrj/Krapack.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Ser.Razy.11068?

Ser.Razy.11068 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment