Malware

Ser.Razy.495 (file analysis)

Malware Removal

The Ser.Razy.495 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ser.Razy.495 virus can do?

  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Collects information to fingerprint the system

Related domains:

www.bing.com
www.eyeover.it

How to determine Ser.Razy.495?


File Info:

crc32: 4B02B130
md5: 750fbf1831dd7d271b5838c013d62221
name: lol.exe
sha1: bbc85a50b253112c13e13ba9b67be53d6f66f89d
sha256: d0711bd86c081c1a531607b105e2ac6fe058dda503b6853e9cba03d310ba1d16
sha512: 8b6ea1d2b7faa87c09b0f658738164768bc37489059f6962a668af4c4877990a73e7cd859960b850c5355dae30d55442eeb64564ea8dc22fd224366478c0cb96
ssdeep: 1536:5P+usQdxmHStgdxF8HBLL/SbCr9BFTpG8JGU8YVTPMVuN:t+usQhWTFIBLL+c9VJrN2VuN
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ser.Razy.495 also known as:

BkavW32.AIDetectVM.malware1
DrWebTrojan.PWS.Stealer.25040
MicroWorld-eScanGen:Variant.Ser.Razy.495
FireEyeGeneric.mg.750fbf1831dd7d27
Qihoo-360Generic/HEUR/QVM20.1.6755.Malware.Gen
McAfeeGenericRXHU-GR!750FBF1831DD
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusSpyware ( 0053d5ad1 )
BitDefenderGen:Variant.Ser.Razy.495
K7GWSpyware ( 0053d5ad1 )
Cybereasonmalicious.831dd7
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34130.euW@a8ijgpn
CyrenW32/Trojan.CAAX-0370
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
GDataGen:Variant.Ser.Razy.495
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojanSpy:Win32/Generic.92164f87
NANO-AntivirusTrojan.Win32.Stealer.frdnip
AegisLabTrojan.Win32.Generic.4!c
RisingSpyware.Agent!8.C6 (CLOUD)
Ad-AwareGen:Variant.Ser.Razy.495
EmsisoftGen:Variant.Ser.Razy.495 (B)
ComodoMalware@#t0bo20rbshzq
F-SecureTrojan.TR/AD.Khalesi.kevpd
ZillyaTrojan.Agent.Win32.1300119
TrendMicroTROJ_GEN.R002C0PG320
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
IkarusTrojan-Spy.Agent
JiangminTrojan.Generic.dkuxp
WebrootW32.Trojan.Gen
AviraTR/AD.Khalesi.kevpd
MAXmalware (ai score=82)
Antiy-AVLTrojan/Win32.Fuerboos
Endgamemalicious (high confidence)
ArcabitTrojan.Ser.Razy.495
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Malware/Win32.Generic.C2792519
Acronissuspicious
VBA32BScope.Trojan.Fuerboos
ALYacGen:Variant.Ser.Razy.495
MalwarebytesSpyware.PasswordStealer
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Spy.Agent.PNJ
TrendMicro-HouseCallTROJ_GEN.R002C0PG320
TencentWin32.Trojan.Generic.Aeod
YandexTrojan.Agent!xn73LY1TkUg
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Generic.AC.453F64
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ser.Razy.495?

Ser.Razy.495 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment