Malware

Kazy.10868 (file analysis)

Malware Removal

The Kazy.10868 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Kazy.10868 virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Kazy.10868?


File Info:

crc32: 2C2FA376
md5: 03bd108a2b8578f288928833fe2b45f6
name: 03BD108A2B8578F288928833FE2B45F6.mlw
sha1: e7664947dfa0923f004cb45b0562d5942f12315f
sha256: 52c8151b7210ea22ab47fb7f77e8c532bce0f98c8dddb86a48bf29386c4f96ea
sha512: 7efdd5efddd70e2155c979d2b1b76be7a7283ed0193a9f4638e2bfe739c67c9fda286ee609aa028884a5107976986cacc067edeb7ad1819124db81c4b0b42967
ssdeep: 6144:uKeOhzmosH9lgV4yP1KK9IuJqx+q4XqFue63XaMUCFo1u2TnlF3w8LJ9b6FIoy6Y:fe9t9CV4y1bIbgTaFPC/UCP2TnP3r9+k
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Kazy.10868 also known as:

BkavW32.MosquitoQKB.Fam.Trojan
K7AntiVirusTrojan ( 001ff90f1 )
LionicHacktool.Win32.Krap.lQVR
Elasticmalicious (high confidence)
DrWebTrojan.Packed.21485
CynetMalicious (score: 100)
ALYacGen:Variant.Kazy.10868
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.110130
SangforTrojan.Win32.MalOb.atFT
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/LockScreen.5eea1e8f
K7GWTrojan ( 001ff90f1 )
Cybereasonmalicious.a2b857
SymantecPacked.Generic.318
ESET-NOD32a variant of Win32/Kryptik.KGK
APEXMalicious
AvastFileRepMalware
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Kazy.10868
NANO-AntivirusTrojan.Win32.Gimemo.daeku
MicroWorld-eScanGen:Variant.Kazy.10868
TencentWin32.Trojan.Gimemo.bkv
Ad-AwareGen:Variant.Kazy.10868
SophosMal/Generic-S
ComodoTrojWare.Win32.TrojanSpy.Zbot.G@2tckk5
BitDefenderThetaGen:NN.ZexaF.34266.wmHfaaYeN8fc
VIPREPacked.Win32.PWSZbot.gen (v)
TrendMicroTROJ_SPYEYE.SMEP
McAfee-GW-EditionW32/Pinkslipbot.gen.ae
FireEyeGeneric.mg.03bd108a2b8578f2
EmsisoftGen:Variant.Kazy.10868 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Gimemo.fy
WebrootW32.Bamital.Gen
AviraTR/Crypt.ULPM.Gen
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.1865F63
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/LockScreen
SUPERAntiSpywareTrojan.Agent/Gen-DitherC
GDataGen:Variant.Kazy.10868
AhnLab-V3Trojan/Win32.Zbot.R2835
McAfeeArtemis!03BD108A2B85
MAXmalware (ai score=100)
VBA32Trojan-Ransom.ScreenLock.Pn
PandaGeneric Malware
TrendMicro-HouseCallTROJ_SPYEYE.SMEP
YandexTrojan.GenAsa!zmZqYZCHD9s
IkarusTrojan.Win32.LockScreen
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Kryptik.NAS!tr
AVGFileRepMalware

How to remove Kazy.10868?

Kazy.10868 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment