Malware

Kazy.190136 removal tips

Malware Removal

The Kazy.190136 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Kazy.190136 virus can do?

  • Unconventionial language used in binary resources: Chinese (Traditional)
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Kazy.190136?


File Info:

crc32: 4E2960E9
md5: d1e6367182223e1945738183ad74d914
name: D1E6367182223E1945738183AD74D914.mlw
sha1: cf87de6dcf7bf0725bdb8bb8fff2fe58bd17ad7b
sha256: d256ae4c9d221f879e8d714d1e19cfb761098938a57302f66f48916487d40ea3
sha512: 7c507709cf273bef3fb44f4d69b4d4788fc125e959228dcca53b30d758af48d20c07e30bb629739f49df0ca09a446ae5adb000aa94cf779e9c7692a1c2397d7b
ssdeep: 192:eNCPz3Rli0QkrmGgbwB6nADHXR2i9ItsLBtbQ8+QyBVjuZONG2nqaFXQcjlUaWNS:egbnvgb5nABge0bHjuh2tFXBUWA8mmWK
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (C) Microsoft Corporation. All rights reserved.
InternalName: ICWRMIND
FileVersion: 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
CompanyName: Microsoft Corporation
ProductName: Microsoft(R) Windows(R) Operating System
ProductVersion: 6.00.2900.2180
FileDescription: Internet Connection Wizard Reminder
OriginalFilename: ICWRMIND.EXE
Translation: 0x0404 0x04b0

Kazy.190136 also known as:

K7AntiVirusRiskware ( 0040eff71 )
LionicTrojan.Win32.PornoBlocker.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
ALYacGen:Variant.Kazy.190136
CylanceUnsafe
AlibabaRansom:Win32/PornoBlocker.526f9f4e
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.182223
SymantecTrojan.Gen.2
APEXMalicious
AvastWin32:Katusha-BE [Trj]
KasperskyTrojan-Ransom.Win32.PornoBlocker.ekle
BitDefenderGen:Variant.Kazy.190136
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanGen:Variant.Kazy.190136
TencentWin32.Trojan.Pornoblocker.Wrzy
Ad-AwareGen:Variant.Kazy.190136
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34142.bm0@am2FR6gb
McAfee-GW-EditionBehavesLike.Win32.Infected.mt
FireEyeGen:Variant.Kazy.190136
EmsisoftGen:Variant.Kazy.190136 (B)
JiangminPacked.Katusha.anf
AviraTR/Patched.Gen2
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASBOL.95A2
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Kazy.D2E6B8
GDataGen:Variant.Kazy.190136
McAfeeArtemis!D1E636718222
MAXmalware (ai score=82)
VBA32suspected of Trojan.Downloader.gen
PandaTrj/CI.A
IkarusPacker.Win32.Katusha
FortinetW32/PornoBlocker.EKLE!tr
AVGWin32:Katusha-BE [Trj]
Paloaltogeneric.ml

How to remove Kazy.190136?

Kazy.190136 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment