Malware

Kazy.16950 removal instruction

Malware Removal

The Kazy.16950 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Kazy.16950 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Attempts to disable UAC
  • Disables Windows firewall
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Kazy.16950?


File Info:

name: 8D27F53F8F185B0149CB.mlw
path: /opt/CAPEv2/storage/binaries/537939beef54d5af1023a9f863f3d18994d4852c46701d0213982fc241d2e9ec
crc32: B4A3F3F4
md5: 8d27f53f8f185b0149cbeabfdf5a48d2
sha1: 0ee02ccea1aebd1b681b089b06cf8c8847ff6c2a
sha256: 537939beef54d5af1023a9f863f3d18994d4852c46701d0213982fc241d2e9ec
sha512: 3a016f152df513803f89a9041e18393711468d81f902cba1a6e53e1e600e9e75dfda5d91fb94aaa12e093c213d21929ddf2c637c8342289f6fca2491126bbf5a
ssdeep: 6144:uaywxPN2FMhuv1jY36D5Ak0EeDOM9vS6v7oDrYLC:Uw7t36j9eDrvLEoLC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T156241242A7D91C52E674D6BB6002E7F7E122D916FD6C9340972F0F03DEF8B50A2A0A47
sha3_384: c59c7036bd33d780de5415c9aa9b80198ceac40a9ae66030ee571cc235dd779b41a20cb2417fb6f7ac0395947c95ccdc
ep_bytes: 60be00f0d1008dbe00206effc7870cd0
timestamp: 2008-01-06 10:50:40

Version Info:

0: [No Data]

Kazy.16950 also known as:

BkavW32.MosquitoQKK.Fam.Trojan
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Kazy.16950
FireEyeGeneric.mg.8d27f53f8f185b01
McAfeeArtemis!8D27F53F8F18
CylanceUnsafe
ZillyaTrojan.PornoBlocker.Win32.2298
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( f1000f011 )
AlibabaTrojan:Win32/Obfuscator.bcfb9dd0
K7GWTrojan ( f1000f011 )
Cybereasonmalicious.f8f185
BitDefenderThetaGen:NN.ZexaF.34212.nmHfa0YV61cc
VirITTrojan.Win32.Dnldr21.CEUM
ESET-NOD32Win32/Delf.QAY
TrendMicro-HouseCallMal_Kryptik-3
Paloaltogeneric.ml
ClamAVWin.Trojan.Pornoblocker-241
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Kazy.16950
NANO-AntivirusTrojan.Win32.ULPM.kgznb
ViRobotTrojan.Win32.A.PornoBlocker.224336[UPX]
AvastFileRepMalware
TencentWin32.Trojan.Falsesign.Ebgx
Ad-AwareGen:Variant.Kazy.16950
EmsisoftGen:Variant.Kazy.16950 (B)
ComodoMalware@#1pjsb5ppmw5rr
DrWebTrojan.DownLoader21.38388
VIPREPacked.Win32.PWSZbot.gen (v)
TrendMicroMal_Kryptik-3
McAfee-GW-EditionW32/Pinkslipbot.gen.ae
SophosMal/Generic-R + Mal/EncPk-ZC
APEXMalicious
GDataGen:Variant.Kazy.16950
JiangminTrojan/Generic.edjy
WebrootW32.Malware.Gen
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.AGeneric
KingsoftWin32.Heur.KVMH019.a.(kcloud)
ArcabitTrojan.Kazy.D4236
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Tofumanics.C
CynetMalicious (score: 100)
VBA32Trojan.Zeus.EA.0999
ALYacGen:Variant.Kazy.16950
MalwarebytesMalware.Heuristic.1003
IkarusTrojan-PWS.Win32.Zbot
RisingTrojan.Occamy!8.F1CD (CLOUD)
YandexTrojan.Delf!tRdKGRta1Us
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7164915.susgen
AVGFileRepMalware
PandaGeneric Malware

How to remove Kazy.16950?

Kazy.16950 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment