Malware

How to remove “Kazy.124728”?

Malware Removal

The Kazy.124728 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Kazy.124728 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Kazy.124728?


File Info:

crc32: 08BC62E2
md5: 00814e144acfa0aedffa4ba20ba25961
name: cadv2.5.55you.com.exe
sha1: 72c86ec52ff69a9c8e55ab969a09af2869eff53c
sha256: b5f23a8d651259d4cf592cf2202dffd41d586cc1a5817fd73b794f66db27ca06
sha512: f25ea2a77c569abe2103fb6dfaf5862acf192291b7712eef3d1ce5985dc8690f64fe3344da0f914610834c868aa731bafc8f4f28fd7bbc19ca84c87f05b4724a
ssdeep: 49152:UCwNnXNqHCoiohsGBN2j3WNey70piuqx+tQzNTJnRVG8KisRyDa:UCSndqHCo3hr63Yey4piXnNNRVQ8a
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: x5c0fx9f99x8f6fx4ef6x5de5x4f5cx5ba4x7248x6743x6240x6709
FileVersion: 1.1.0.0
CompanyName: x5c0fx9f99x8f6fx4ef6x5de5x4f5cx5ba4(QQ:583371958)
Comments: CADx6740x6bd2x8f6fx4ef6x5b89x88c5x7a0bx5e8f
ProductName: CADx6740x6bd2x8f6fx4ef6x5b89x88c5x7a0bx5e8f
ProductVersion: 1.1.0.0
FileDescription: CADx6740x6bd2x8f6fx4ef6x5b89x88c5x7a0bx5e8f
Translation: 0x0804 0x04b0

Kazy.124728 also known as:

MicroWorld-eScanGen:Variant.Kazy.124728
FireEyeGeneric.mg.00814e144acfa0ae
McAfeeArtemis!00814E144ACF
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Kazy.124728
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.44acfa
TrendMicroTROJ_SPNR.38HQ13
F-ProtW32/Trojan.CLL.gen!Eldorado
SymantecTrojan.Gen
APEXMalicious
ClamAVWin.Adware.Agent-1294915
GDataGen:Variant.Kazy.124728
AlibabaTrojan:Application/Generic.0525ccc0
NANO-AntivirusTrojan.Win32.TrjGen.cudtzt
AegisLabTrojan.Win32.Kazy.4!c
AvastWin32:Malware-gen
TencentWin32.Trojan.Spnr.Dav
Endgamemalicious (moderate confidence)
SophosGeneric PUA HC (PUA)
ComodoMalware@#2wsakfykx0ice
DrWebTrojan.Click2.64462
ZillyaTrojan.Genome.Win32.214756
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Flyagent.tc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Kazy.124728 (B)
IkarusTrojan.Win32.Sasfis
CyrenW32/Trojan.CLL.gen!Eldorado
JiangminTrojanDropper.Flystud.bi
WebrootW32.Malware.Gen
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Win32.Genome
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Kazy.D1E738
SUPERAntiSpywareTrojan.Agent/Gen-Genome
Acronissuspicious
VBA32Trojan.Genome.ai
MAXmalware (ai score=99)
Ad-AwareGen:Variant.Kazy.124728
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
TrendMicro-HouseCallTROJ_SPNR.38HQ13
RisingTrojan.Win32.Generic.14501E91 (C64:YzY0Oh/Va8xEY+bO)
YandexRootkit.Agent!VjquwSXHwRQ
SentinelOneDFI – Malicious PE
MaxSecureTrojan.Malware.4945242.susgen
FortinetW32/Genome.AIWUL!tr
BitDefenderThetaGen:NN.ZexaF.34098.4nKfamXjDagb
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Kazy.124728?

Kazy.124728 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment