Malware

Should I remove “Kazy.475859”?

Malware Removal

The Kazy.475859 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Kazy.475859 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Arabic
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Kazy.475859?


File Info:

name: 661431B54377684DD1E0.mlw
path: /opt/CAPEv2/storage/binaries/f88604acd01a3dfe9a48249433019ceb245101a16243a39ca3869bf949bbde32
crc32: D4FD4C13
md5: 661431b54377684dd1e0364cc755486d
sha1: 016bcd88b2b400ae40debe10a4492395dec1ec8b
sha256: f88604acd01a3dfe9a48249433019ceb245101a16243a39ca3869bf949bbde32
sha512: f9eb657349dd353c5826ea32aaa697d11295c447884ca654c9895c62182bea9410104861b7dda4ae7159e9baf39fcad3e4d04042f179494a4a3d68684e137729
ssdeep: 6144:/ulZ5g27C5Brl3QbaYzML+Q22uThc3Z47oxSdJqlcB+7keUkduRK5r+:g55C591XYzc+uuThcJ47GVRduSr+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13D5412176B906410FEDDCE7DB186FB4D07DF72250B0B1D0B0AD06EE9B9A56D0E89029B
sha3_384: ae340dd4028dbe995b3d17a6d968ba05a217a36010d263d9f5ea48a8effa35b7e87127b9f24a6a28b33ecee7fde391f2
ep_bytes: 558bec81ec1c010000b991000000898d
timestamp: 2011-09-17 10:45:22

Version Info:

ProductName: Marsukafe® Visatl Studio® 2010
FileVersion: 10.3.45883.4952
ProductVersion: 10.3.45883.4952
InternalName: denrinko.exe
OriginalFilename: denrinko.exe
Translation: 0x0409 0x04b0

Kazy.475859 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Kazy.475859
FireEyeGeneric.mg.661431b54377684d
CAT-QuickHealFraudTool.Security
McAfeeTrojan-FFFI!661431B54377
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.856611
SangforTrojan.Win32.Generic.ky
K7AntiVirusTrojan ( 0055dd191 )
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.543776
BaiduWin32.Trojan.Kryptik.je
VirITTrojan.Win32.Siggen6.WKA
CyrenW32/A-44cef87e!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.CNRZ
APEXMalicious
ClamAVWin.Trojan.Agent-1206362
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Kazy.475859
NANO-AntivirusTrojan.Win32.Zbot.dgzlxl
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AvastWin32:Agent-AUYE [Trj]
TencentTrojan.Win32.Zbot.c
EmsisoftGen:Variant.Kazy.475859 (B)
ComodoTrojWare.Win32.Kryptik.CNNY@5ggyvf
DrWebTrojan.Siggen6.15132
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_ZBOT.SMX1
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
SophosML/PE-A + Troj/Agent-AIIM
IkarusTrojan-Spy.Zbot
JiangminTrojanSpy.Zbot.egkh
AviraHEUR/AGEN.1227066
Antiy-AVLTrojan/Generic.ASMalwS.C768E7
KingsoftWin32.Troj.Zbot.uk.(kcloud)
MicrosoftPWS:Win32/Zbot
GDataGen:Variant.Kazy.475859
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.ZBot.R121772
BitDefenderThetaGen:NN.ZexaF.34182.ru1@a4UJodCO
ALYacGen:Variant.Kazy.475859
MAXmalware (ai score=84)
VBA32TrojanSpy.Zbot
MalwarebytesBackdoor.Agent.RND
TrendMicro-HouseCallTSPY_ZBOT.SMX1
RisingTrojan.Win32.Generic.1790C1E0 (C64:YzY0OgiBjk8lgodz)
YandexTrojan.Kryptik!ChhZQOkg7DQ
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.CJJL!tr
AVGWin32:Agent-AUYE [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Kazy.475859?

Kazy.475859 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment