Malware

Ser.Razy.469 (file analysis)

Malware Removal

The Ser.Razy.469 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ser.Razy.469 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Deletes its original binary from disk
  • Attempts to modify proxy settings
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
zipansion.com
hurirk.net
a.tomx.xyz

How to determine Ser.Razy.469?


File Info:

crc32: B6BC2C66
md5: 1035c1668a4cce1de45c7f08ca2f6089
name: 1035C1668A4CCE1DE45C7F08CA2F6089.mlw
sha1: a22f7113130e48c3da8a0e7a1fee49d0959102e5
sha256: 9521da7ae435fef3d9e6bc4d585747a578640aae6295b71aad2208638b7d0f9a
sha512: 8383c516bd8167452dec79672e75c5681618bfe2835e017340fcbef8a333da5e00315b5deda9a92a5faa80cd3b027096b224eb9fd6ecfbacc4fa7f536c0d76d7
ssdeep: 24576:2iWgpEO98TlH/jGKE9wKr0kjyp9t60YutJgFNzsN71z/pM1j//E/HcfgfNNWTFW:2LgOnHLGKSwKr0xt+FxU71mpE/AcbWT
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

0: [No Data]

Ser.Razy.469 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004bcce41 )
Elasticmalicious (high confidence)
DrWebTrojan.Packed2.43250
CynetMalicious (score: 100)
ALYacGen:Variant.Ser.Razy.469
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7GWTrojan ( 00539ec91 )
Cybereasonmalicious.68a4cc
CyrenW32/Injector.AGG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EAPQ
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
ClamAVWin.Malware.Razy-9857221-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ser.Razy.469
MicroWorld-eScanGen:Variant.Ser.Razy.469
TencentMalware.Win32.Gencirc.10ce3bbe
Ad-AwareGen:Variant.Ser.Razy.469
SophosTroj/Agent-BHBT
ComodoPacked.Win32.MUPX.Gen@24tbus
BitDefenderThetaGen:NN.ZexaF.34170.DnZ@aujGNte
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.1035c1668a4cce1d
EmsisoftGen:Variant.Ser.Razy.469 (B)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_94%
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Generic.ASCommon.1FB
GDataGen:Variant.Ser.Razy.469
AhnLab-V3PUP/Win32.Downloader.R237415
MAXmalware (ai score=80)
VBA32BScope.Trojan.Wacatac
MalwarebytesSpyware.PasswordStealer.UPX
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.D238 (CLASSIC)
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.EAHK!tr
AVGWin32:MalwareX-gen [Trj]

How to remove Ser.Razy.469?

Ser.Razy.469 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment