Malware

Kazy.183135 (file analysis)

Malware Removal

The Kazy.183135 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Kazy.183135 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Kazy.183135?


File Info:

name: 49F9A9FDC86B0BE330B4.mlw
path: /opt/CAPEv2/storage/binaries/007e1d2458621c7e596bc11f272df784407aeb0c6c641dca727421cc50a63fcc
crc32: B5D83FF2
md5: 49f9a9fdc86b0be330b44061130412ca
sha1: 2b923c3c087553a89f9d86a2d5e6575ee9356769
sha256: 007e1d2458621c7e596bc11f272df784407aeb0c6c641dca727421cc50a63fcc
sha512: b22f14f48b3c78bb207e953fbb932a5d75ae4d914ee61d1aeb2d0f7cc9c7c75ed13095300a5f31cf116beaeaaea672e8c3056e78c094222e5be800b4cefcb714
ssdeep: 6144:pEEjsozQErJsi+hm/vZPYMsMLO0ihWXGHe:pEVoMENsiWm/vZPjsgOLhWX9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T178241220E744AC35EEF66173ADBB4BB1E9FA49FA2611515787B01DB23019FC9820F364
sha3_384: 7d6bb747c433beb938b5de7ba005cfc5ef900b98c6d924be2f21f2fa7973982381e5f377a7082aeb21feb0d79f674b45
ep_bytes: 558bec81ec40010000b9cb000000894d
timestamp: 2012-10-17 01:29:28

Version Info:

FileVersion: 222.27.51277.36009
CompanyName: OPEra sOfTWAre
FileDescription: 0Mdn1H7cCFus
LegalCopyright: sdSZ
InternalName: eKRtz
OriginalFilename: KanAHB
ProductName: kOtrtvBpQKiIwz
ProductVersion: 113.67.43526.40746
Translation: 0x0409 0x04b0

Kazy.183135 also known as:

BkavW32.AIDetect.malware2
DrWebTrojan.DownLoader9.33330
MicroWorld-eScanGen:Variant.Kazy.183135
FireEyeGeneric.mg.49f9a9fdc86b0be3
ALYacGen:Variant.Kazy.183135
CylanceUnsafe
SangforTrojan.Win32.EB.5
K7GWHacktool ( 700007861 )
Cybereasonmalicious.dc86b0
BitDefenderThetaGen:NN.ZexaF.34638.nu1@amOpc3pi
CyrenW32/Yakes.R.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.BDEE
TrendMicro-HouseCallTSPY_ZBOT.SMODN
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Kazy.183135
NANO-AntivirusTrojan.Win32.Luder.cruatb
SUPERAntiSpywareTrojan.Agent/Gen-Zegost
AvastWin32:Kryptik-LXT [Trj]
TencentTrojan.Win32.Zbot.c
Ad-AwareGen:Variant.Kazy.183135
EmsisoftGen:Variant.Kazy.183135 (B)
ComodoMalware@#1vfv9yfeucjx9
F-SecureTrojan.TR/PSW.Fareit.EB.5
BaiduWin32.Trojan.Kryptik.ej
ZillyaWorm.Luder.Win32.849
TrendMicroTSPY_ZBOT.SMODN
McAfee-GW-EditionBehavesLike.Win32.Virut.dc
SentinelOneStatic AI – Malicious PE
SophosML/PE-A + Troj/Zbot-JMR
IkarusTrojan.Win32.Rerdom
GDataGen:Variant.Kazy.183135
JiangminTrojan.Generic.fcrgj
AviraTR/PSW.Fareit.EB.5
Antiy-AVLTrojan/Win32.Unknown
ArcabitTrojan.Kazy.D2CB5F
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Vigorf.A
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Luder.R69698
McAfeeGeneric-FAJG!49F9A9FDC86B
VBA32BScope.Trojan-Dropper.2551
MalwarebytesBackdoor.Agent.RND
APEXMalicious
RisingTrojan.Win32.Generic.151FF08C (C64:YzY0Ou4T28QtUDscJjRGm8puf5s)
YandexTrojan.Kryptik!NLpA7c2pO9c
MAXmalware (ai score=80)
FortinetW32/Kryptik.CAAF!tr
AVGWin32:Kryptik-LXT [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Kazy.183135?

Kazy.183135 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment