Malware

How to remove “Ser.Razy.13995 (B)”?

Malware Removal

The Ser.Razy.13995 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ser.Razy.13995 (B) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Czech
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Anomalous binary characteristics

How to determine Ser.Razy.13995 (B)?


File Info:

crc32: 4D9DD230
md5: a1447468d1033c707b4d9ea7e4c7f38f
name: A1447468D1033C707B4D9EA7E4C7F38F.mlw
sha1: 5ab71940d0b1a9b41497530b9b22bfc2ffe3ba4a
sha256: a4a8c3b7c05353613370a1e1a3e6a93dd246668faefa546b7519b25fd1b6ffd0
sha512: c014bec8690c733d082154bfc8ab38dcc898c4769b715233c482dd8eb5d4401762e6cb6c002dd6fa0cd5ac00284575ab6805feddf59c4f60ca0b09cb8301596d
ssdeep: 3072:WK2F+uTUkmvR1wk56RgH8TnLWlRUrn4Pl0UPJTzUuPcYc8XmFOM:WK2IkCRvGfLHEeYb4
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: sgfnghmj.exe
FileVersion: 8.4.3.12
Translation: 0x0809 0x04b0

Ser.Razy.13995 (B) also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053d5971 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.25799
CynetMalicious (score: 100)
CAT-QuickHealRansom.GandCrab3.S3494929
ALYacTrojan.Ransom.GandCrab
CylanceUnsafe
ZillyaTrojan.GenericKD.Win32.154193
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/GandCrab.91709770
K7GWTrojan ( 0053d5971 )
Cybereasonmalicious.8d1033
CyrenW32/Ransom.LB.gen!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GJRD
APEXMalicious
AvastFileRepMalware
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ser.Razy.13995
NANO-AntivirusTrojan.Win32.GandCrypt.fidgey
ViRobotTrojan.Win32.R.Agent.212992.AJ
SUPERAntiSpywareTrojan.Agent/Gen-Emotet
MicroWorld-eScanGen:Variant.Ser.Razy.13995
TencentWin32.Trojan.Generic.Ljjo
Ad-AwareGen:Variant.Ser.Razy.13995
SophosMal/Generic-S + Mal/GandCrab-G
ComodoMalware@#1xoutjysw3f2o
BitDefenderThetaGen:NN.ZexaF.34692.nu0@ayv6LkiG
VIPRETrojan.Win32.Generic!BT
TrendMicroMal_HPGen-50
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.a1447468d1033c70
EmsisoftGen:Variant.Ser.Razy.13995 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.GandCrypt.ip
AviraTR/GandCrab.juq
eGambitUnsafe.AI_Score_96%
Antiy-AVLTrojan/Generic.ASMalwS.2769B52
MicrosoftRansom:Win32/GandCrab.AU!bit
ArcabitTrojan.Ser.Razy.D36AB
AegisLabTrojan.Win32.GandCrypt.j!c
GDataGen:Variant.Ser.Razy.13995
AhnLab-V3Win-Trojan/MalPe34.Suspicious.X2029
Acronissuspicious
McAfeePacked-FKN!A1447468D103
MalwarebytesTrojan.Agent
PandaTrj/GdSda.A
TrendMicro-HouseCallMal_HPGen-50
RisingMalware.Obscure/Heur!1.9E03 (CLASSIC)
YandexTrojan.GenAsa!ygqA0+tuwHI
IkarusTrojan-Downloader.Win32.Zurgop
MaxSecureRansomeware.CRAB.gen
FortinetW32/Kryptik.GKJF!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Ser.Razy.13995 (B)?

Ser.Razy.13995 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment