Malware

Kazy.11649 (B) removal tips

Malware Removal

The Kazy.11649 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Kazy.11649 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Code injection with CreateRemoteThread in a remote process
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings
  • Attempts to disable browser security warnings
  • Harvests cookies for information gathering

How to determine Kazy.11649 (B)?


File Info:

name: 55A58B866F81376112CC.mlw
path: /opt/CAPEv2/storage/binaries/f707e89858c89fa94cccafd81e455c4f1de2f3b16a77b44b4975bbfd3cf8a8f4
crc32: C73FEFE7
md5: 55a58b866f81376112ccc0447cf14d6f
sha1: 395e097eccb8d3197c53625d009e5e40dad84c6c
sha256: f707e89858c89fa94cccafd81e455c4f1de2f3b16a77b44b4975bbfd3cf8a8f4
sha512: 5e45487e7af1147de1f89c0d3da924870801aed6032a203b30acd3fdc8c96b51559ef7ab1a46d81efd3a797a21407f0b68d2f6c23c91143281c46416e4ddf636
ssdeep: 6144:6BB9bsxFH2vFtGlRv9gHCKt9gc35W8UvPle9M:+IxcvQlgiKTWtvPU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16424E140EA855566D7D8033DFC125667C5563C78AFE3AE022A71BCC239BD7D2C827A23
sha3_384: bae3dba8fcb0f972b43d044ee9a367000b9417e284f7f96f37434d25d28f751a8ef7d719f147336b3d1172dc462b15e5
ep_bytes: 558bec83c4c8ff75ece8fff9fdffc9c3
timestamp: 2005-03-06 13:37:24

Version Info:

CompanyName: MoRUN.net
FileDescription: MoRUN.net Sticker Lite
FileVersion: 6.3
InternalName: Sticker.exe
LegalCopyright: 2002-2010 (c) MoRUN.net. All rights reserved.
OriginalFilename: Sticker.exe
ProductName: MoRUN.net Sticker Lite
ProductVersion: 6.3
Translation: 0x0409 0x04e4

Kazy.11649 (B) also known as:

BkavW32.AIDetect.malware1
LionicHacktool.Win32.Krap.x!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Kazy.11649
FireEyeGeneric.mg.55a58b866f813761
CAT-QuickHealWorm.SlenfBot.Gen
ALYacGen:Variant.Kazy.11649
CylanceUnsafe
VIPREPacked.Win32.PWSZbot.gen (v)
SangforSuspicious.Win32.Save.a
K7AntiVirusSpyware ( 0055e3db1 )
AlibabaTrojanSpy:Win32/EyeStye.17aec250
K7GWSpyware ( 0055e3db1 )
Cybereasonmalicious.66f813
VirITTrojan.Win32.SpySweep.CZZ
CyrenW32/S-b328bb35!Eldorado
SymantecW32.Qakbot!gen5
ESET-NOD32Win32/Spy.SpyEye.CA
APEXMalicious
Paloaltogeneric.ml
KasperskyPacked.Win32.Krap.ae
BitDefenderGen:Variant.Kazy.11649
NANO-AntivirusTrojan.Win32.Krap.edlvrp
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AvastWin32:Malware-gen
TencentWin32.Packed.Krap.Swkz
Ad-AwareGen:Variant.Kazy.11649
EmsisoftGen:Variant.Kazy.11649 (B)
ComodoTrojWare.Win32.TrojanSpy.Zbot.G@2tckk5
DrWebTrojan.PWS.SpySweep.2027
ZillyaTrojan.SpyEye.Win32.948
TrendMicroBKDR_QAKBOT.SMG
McAfee-GW-EditionPWS-Spyeye.fe
SophosML/PE-A + Mal/FakeAV-BW
IkarusTrojan-Spy.Win32.Zbot
GDataGen:Variant.Kazy.11649
JiangminTrojanSpy.SpyEyes.bfy
AviraTR/Crypt.XPACK.Gen
eGambitGeneric.Malware
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.18747D8
ZoneAlarmPacked.Win32.Krap.ae
MicrosoftTrojan:Win32/EyeStye.H
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.R2835
McAfeePWS-Spyeye.fe
VBA32Trojan.Zeus.EA.0999
TrendMicro-HouseCallBKDR_QAKBOT.SMG
RisingSpyware.SpyEye!8.271 (CLOUD)
YandexTrojanSpy.SpyEye!+Fyh+vKN2sU
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.NAS!tr
BitDefenderThetaGen:NN.ZexaF.34212.nq0@a4z2EShc
AVGWin32:Malware-gen
PandaBck/Qbot.AO
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Kazy.11649 (B)?

Kazy.11649 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment