Malware

Ser.Razy.7434 removal guide

Malware Removal

The Ser.Razy.7434 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ser.Razy.7434 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • CAPE detected the Sakula malware family
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities

How to determine Ser.Razy.7434?


File Info:

name: D91894337EEA7248622A.mlw
path: /opt/CAPEv2/storage/binaries/add3bd0a46ad1b8de3c9cb02d1b6b75a8afb6dcbfc9b0ea8b7e698a1c05dfcc4
crc32: 14514D8B
md5: d91894337eea7248622a17a55094e449
sha1: 8a746cb405710a52189210d099f35e7a32656e8a
sha256: add3bd0a46ad1b8de3c9cb02d1b6b75a8afb6dcbfc9b0ea8b7e698a1c05dfcc4
sha512: f35e7146b252657d6b83f5bb16a5caf013f0809407f017218a880cc0dee10f7cc6ddbf81b10794ca89516431b810ef66c4d52ad9ac0d4b2b9e87d5cc67a54288
ssdeep: 384:MnyhSksAVndb4G3w2NMsG9OqvhyY3Q6oVxYwwsRhg7+iXXRodY6kLdAeMa:1hSksandb4GgyMsp4hyYtoVxYdT7ZXqC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C1131927B64928E6FF9CD7B0A08B8F5BC6F1E65002F9484713D88D45171E26DA36B81F
sha3_384: 4aa1d429a87169c5b0521511ae999f4a6591e8d1a17f6735df3955413a4a4975dabb2f069dc4356c7ecaa90088e37e15
ep_bytes: 31c0eb605351e82d710000e82e710000
timestamp: 2014-04-30 16:29:02

Version Info:

0: [No Data]

Ser.Razy.7434 also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Ser.Razy.7434
ClamAVWin.Malware.Amhfxaazhpc-6855566-0
FireEyeGeneric.mg.d91894337eea7248
CAT-QuickHealTrojanAPT.LecnaCShip.MUE.Z4
ALYacGen:Variant.Ser.Razy.7434
CylanceUnsafe
ZillyaTrojan.Generic.Win32.1531863
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004b506c1 )
K7GWTrojan ( 004b506c1 )
Cybereasonmalicious.37eea7
VirITTrojan.Win32.Injectir.CCS
CyrenW32/Shyape.D.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Shyape.J
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ser.Razy.7434
NANO-AntivirusTrojan.Win32.Shyape.fwyawt
AvastWin32:Cleaman-K [Trj]
TencentTrojan.Win32.Shyape.za
Ad-AwareGen:Variant.Ser.Razy.7434
TACHYONTrojan-Dropper/W32.Agent.44032.DG
EmsisoftGen:Variant.Ser.Razy.7434 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.Siggen7.10761
VIPREGen:Variant.Ser.Razy.7434
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.pm
Trapminemalicious.high.ml.score
SophosML/PE-A + Troj/Agent-BAXF
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.bcaze
AviraHEUR/AGEN.1204963
Antiy-AVLTrojan/Generic.ASMalwS.3303
MicrosoftBackdoor:Win32/Plugx.N!dha
GDataWin32.Trojan.PSE.10NWIM3
GoogleDetected
AhnLab-V3Backdoor/Win.Generic.R438934
Acronissuspicious
McAfeeGenericRXNO-AD!D91894337EEA
MAXmalware (ai score=89)
VBA32Trojan.Sakurel
MalwarebytesGeneric.Trojan.Malicious.DDS
RisingTrojan.Shyape!1.A750 (CLASSIC)
YandexTrojan.Agent!QgFnLZ444Qc
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Shyape.J!tr
BitDefenderThetaAI:Packer.2052C1CB1E
AVGWin32:Cleaman-K [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Ser.Razy.7434?

Ser.Razy.7434 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment