Malware

Kazy.20579 (B) removal guide

Malware Removal

The Kazy.20579 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Kazy.20579 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)

How to determine Kazy.20579 (B)?


File Info:

name: CBC8C8119DBAA7F07F79.mlw
path: /opt/CAPEv2/storage/binaries/be2b1a9ba2c125b0009169d05a533ddf728cf852e042c2b1b5a40dbfc5d87748
crc32: 0EC10BE8
md5: cbc8c8119dbaa7f07f79576873bba1ee
sha1: 10f3d5ac955f711787c09c62201d45da1afe56b6
sha256: be2b1a9ba2c125b0009169d05a533ddf728cf852e042c2b1b5a40dbfc5d87748
sha512: 3d03ae4b894b899b0d4fdea17d488b02ea0c055a39e9833ec9803f464187cd44160e6dacd45723bbdb84891b1bcbc38d462f8e8458c4d5eb6ef7609d14020f06
ssdeep: 1536:FNksBfSWOc+lCL8ffV+Hl+z0sf+bnSGqGm8rU00/CiT7uh+cahoawJke:HkofSXcGCofMHlHsfESGqyx0tX0shwX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D17301A7B258C0F7F02FEB3A0095C45748A22E418A37538968C6374F7F7B4CA5A71C22
sha3_384: 60cbf4ccdf8be3268556564e532adfb5d2db56496e9b0896e086796f14715ef3bd29aa81f2e1c3fdc39718176c5627fd
ep_bytes: 60be007040008dbe00a0ffff5783cdff
timestamp: 2009-08-12 06:52:10

Version Info:

CompanyName: Kdscoy Lrv Ahiwf Vx
FileDescription: Htuniwno. Umrl, Tebq
FileVersion: 2.5.5000.4600
InternalName: Nbakmc Uggfn, Fxr
LegalCopyright: Bjpdym
OriginalFilename: Tvpnpwa Gcm,
ProductName: Smov
ProductVersion: 2.5.5000.4600
Translation: 0x0409 0x04b0

Kazy.20579 (B) also known as:

BkavW32.RimecudQKI.Fam.Trojan
LionicTrojan.Win32.Generic.lmvm
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Kazy.20579
ZillyaWorm.Palevo.Win32.105389
SangforTrojan.Win32.Rimecud.A
K7AntiVirusTrojan ( 0000a64c1 )
AlibabaTrojan:Win32/Rimecud.0df9e4d1
K7GWTrojan ( 0000a64c1 )
Cybereasonmalicious.19dbaa
CyrenW32/Palevo.H.gen!Eldorado
SymantecW32.Pilleuz!gen19
ESET-NOD32a variant of Win32/Kryptik.MZD
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Kazy.20579
NANO-AntivirusTrojan.Win32.Crypted.cqeohz
MicroWorld-eScanGen:Variant.Kazy.20579
TencentWin32.Trojan.Generic.Tcce
Ad-AwareGen:Variant.Kazy.20579
EmsisoftGen:Variant.Kazy.20579 (B)
ComodoTrojWare.Win32.Kryptik.MZA@4gtbw2
F-SecureTrojan.TR/Crypt.XPACK.Gen2
DrWebTrojan.Packed.21635
VIPRETrojan.Win32.Kryptik.mzd (v)
TrendMicroWORM_PALEVO.SMAG
McAfee-GW-EditionBehavesLike.Win32.Rimecud.lc
FireEyeGeneric.mg.cbc8c8119dbaa7f0
SophosMal/Generic-R + Mal/Zbot-FH
SentinelOneStatic AI – Malicious PE
JiangminPack.Mal.AntiVM
AviraTR/Crypt.XPACK.Gen2
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASMalwS.4DEC3B
MicrosoftTrojan:Win32/Rimecud.A
ArcabitTrojan.Kazy.D5063
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Kazy.20579
AhnLab-V3Trojan/Win32.Kazy.R28019
Acronissuspicious
McAfeeArtemis!CBC8C8119DBA
VBA32BScope.P2P-Worm.Palevo
CylanceUnsafe
PandaTrj/Rimecud.a
TrendMicro-HouseCallWORM_PALEVO.SMAG
RisingWorm.Palevo!8.171 (CLOUD)
YandexTrojan.GenAsa!QI/hyMoAkFc
IkarusTrojan.Win32.Crypt
eGambitUnsafe.AI_Score_99%
FortinetW32/KRYPTK.SMU2!tr
BitDefenderThetaGen:NN.ZexaF.34182.emKfaq@Ldeoi
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_90% (W)
MaxSecureTrojan.Malware.7164915.susgen

How to remove Kazy.20579 (B)?

Kazy.20579 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment