Malware

Ser.Razy.7880 removal

Malware Removal

The Ser.Razy.7880 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ser.Razy.7880 virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Ser.Razy.7880?


File Info:

name: 2AB0768421E9A61101F7.mlw
path: /opt/CAPEv2/storage/binaries/f9ba1ccac1f698b231484566a2ea9b50c3b2a55e3e61d1635467ff711d9dca67
crc32: ED79BFA8
md5: 2ab0768421e9a61101f7134720ee6533
sha1: ac6a1f16bf44846e04bdc46338d07c3e588422b9
sha256: f9ba1ccac1f698b231484566a2ea9b50c3b2a55e3e61d1635467ff711d9dca67
sha512: a50aaaa8c5013dcfe7591a229e4cb7189cb58ad91525d664999401dd7eb35c57cc4f0f34683379b79efd274e944c6128b64160df531640d1922c95ce45228748
ssdeep: 384:JeNkxViq4RvxXAYi+QOiTWRO/bmRodbbHB5sp:JeNkxViqAxrifRTIO/trT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17472C0854B1D5CDECE43543D3A71C7809390722283EFBB662B5459D5A87A0A1CBA8857
sha3_384: bc583b30b617721c70c2c47fc06790ba7beada6e33e01182e344eb6ff7a248530d3a01bc4307056d40278bb3a8ad7acf
ep_bytes: 60be00c040008dbe0050ffff5783cdff
timestamp: 2011-06-09 12:03:42

Version Info:

0: [No Data]

Ser.Razy.7880 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.OnLineGames.d!c
Elasticmalicious (moderate confidence)
DrWebTrojan.PWS.Wsgame.31096
MicroWorld-eScanGen:Variant.Ser.Razy.7880
FireEyeGeneric.mg.2ab0768421e9a611
McAfeePWS-OnlineGames.ok
MalwarebytesGeneric.Malware/Suspicious
SangforSuspicious.Win32.Save.a
K7AntiVirusRiskware ( 0015e4f11 )
AlibabaTrojanPSW:Win32/OnLineGames.2f60ed9c
K7GWRiskware ( 0015e4f11 )
Cybereasonmalicious.6bf448
BitDefenderThetaAI:Packer.9CED34961E
VirITTrojan.Win32.Generic.BZWX
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/PSW.OnLineGames.PGF
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Onlinegames-7223
KasperskyTrojan-GameThief.Win32.OnLineGames.bofk
BitDefenderGen:Variant.Ser.Razy.7880
NANO-AntivirusTrojan.Win32.OnLineGames.cztue
AvastWin32:Evo-gen [Trj]
TACHYONTrojan-PWS/W32.OnLineGames.57944.B
SophosMal/Dropr-C
F-SecureTrojan.TR/Spy.Gen
VIPREGen:Variant.Ser.Razy.7880
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Ser.Razy.7880 (B)
IkarusTrojan-GameThief.Win32.OnLineGames
JiangminTrojan/PSW.OnLineGames.cdvs
WebrootW32.Malware.Gen
VaristW32/OnlineGames.AQ.gen!Eldorado
AviraTR/Spy.Gen
Antiy-AVLTrojan[GameThief]/Win32.OnLineGames
Kingsoftmalware.kb.b.997
XcitiumMalware@#6gw5gnzu33al
ArcabitTrojan.Ser.Razy.D1EC8
ZoneAlarmTrojan-GameThief.Win32.OnLineGames.bofk
GDataGen:Variant.Ser.Razy.7880
GoogleDetected
AhnLab-V3Trojan/Win32.OnlineGameHack.C214251
ALYacGen:Variant.Ser.Razy.7880
MAXmalware (ai score=100)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_ONLINEGAMES_000068f.TOMA
TencentMalware.Win32.Gencirc.115b26d8
YandexTrojan.PWS.OnLineGames!0fk/f4avQfI
SentinelOneStatic AI – Malicious PE
FortinetW32/OnLineGames.BF!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ser.Razy.7880?

Ser.Razy.7880 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment