Malware

About “Kazy.30319” infection

Malware Removal

The Kazy.30319 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Kazy.30319 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

How to determine Kazy.30319?


File Info:

name: C84F7DA3C9B4F55598D9.mlw
path: /opt/CAPEv2/storage/binaries/07bfeedf68b7dc116e4d2a22c0e2c72200c03c4a0cbf505f54034d4a666e01b5
crc32: D1688C41
md5: c84f7da3c9b4f55598d967595a6f28b5
sha1: e9415362cb9287566e8a06fb95dbc0b37a0724b6
sha256: 07bfeedf68b7dc116e4d2a22c0e2c72200c03c4a0cbf505f54034d4a666e01b5
sha512: 6b23c0eba1d48e7ec2127348be4e67c445ed8e1fd4e7a655ea914d3c98e3cfc1e0b9a130b9c1d0147872270c9665925a21fe3903e96ca95a7534ff4795f40555
ssdeep: 3072:t9CIeqC0L0NEY+bsWHgbi8hAzT3QaGOq67BcdsZnLuARuHlAVzKMrOJHjW/LPh:SPqCK0NEbHehhA37Nwc58GFrrOJHjWz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19424237AA624474FD391573C35981160ECA7EAEE74D0AEF8656D10DC9DBFC0E8C08B25
sha3_384: 27b62da58244cded85b101e3f87747f68e8c7bf0e4aea3f96d82089107d10badfff01da91aef621c22a768781b215f68
ep_bytes: 60be006046008dbe00b0f9ff57eb0b90
timestamp: 1996-06-11 12:46:04

Version Info:

CompanyName: Guess After
FileDescription: Trick Flat Puzzle
FileVersion: 119.123.94.35
InternalName: Tulip
LegalCopyright: Copyright © Goon Shoo 2001-2007
OriginalFilename: Lurid.exe
ProductName: Radar
ProductVersion: 119.123.94.35
Translation: 0x0409 0x04b0

Kazy.30319 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoad2.32694
MicroWorld-eScanGen:Variant.Kazy.30319
FireEyeGeneric.mg.c84f7da3c9b4f555
ALYacGen:Variant.Kazy.30319
CylanceUnsafe
ZillyaTrojan.Swisyn.Win32.18307
SangforTrojan.Win32.Seleya.A
K7AntiVirusTrojan ( 0040f49e1 )
AlibabaTrojan:Win32/Obfuscator.c944fb66
K7GWTrojan ( 0040f49e1 )
Cybereasonmalicious.3c9b4f
ArcabitTrojan.Kazy.D766F
BitDefenderThetaAI:Packer.2A0B3A831F
VirITTrojan.Win32.Generic.BKKJ
CyrenW32/Zbot.DA.gen!Eldorado
SymantecTrojan.Gen
ESET-NOD32a variant of Win32/Kryptik.QLA
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Kazy.30319
NANO-AntivirusTrojan.Win32.TrjGen.eutef
AvastFileRepMalware
RisingTrojan.Seleya!8.C9A (CLOUD)
Ad-AwareGen:Variant.Kazy.30319
EmsisoftGen:Variant.Kazy.30319 (B)
ComodoTrojWare.Win32.Trojan.XPACK.Gen@2ho5ur
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.PWSMmorpg.dc
SophosML/PE-A + Mal/Zbot-ASK
IkarusTrojan.Win32.Swisyn
JiangminTrojan/Swisyn.qak
AviraTR/Kryptik.QDM
Antiy-AVLTrojan/Generic.ASMalwS.7C5994
MicrosoftTrojan:Win32/Seleya.A
ViRobotTrojan.Win32.A.Swisyn.220160
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Kazy.30319
Acronissuspicious
McAfeeArtemis!C84F7DA3C9B4
MAXmalware (ai score=100)
VBA32Trojan.Zeus.EA.0999
APEXMalicious
TencentWin32.Trojan.Generic.Sxyd
YandexTrojan.Swisyn!I687jZ6ow00
SentinelOneStatic AI – Malicious PE
FortinetW32/Injector.HVQ!tr
AVGFileRepMalware
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Kazy.30319?

Kazy.30319 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment