Malware

Kazy.55566 removal tips

Malware Removal

The Kazy.55566 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Kazy.55566 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Authenticode signature is invalid

How to determine Kazy.55566?


File Info:

name: 7D8C597A948E98F718B1.mlw
path: /opt/CAPEv2/storage/binaries/f7f356f100aa04dcdb567a87351d175095fd68ad66400f26f0fcc42b56d854fa
crc32: 03B6E58E
md5: 7d8c597a948e98f718b1b076df80d68c
sha1: dc3507fc45d202ae5a0d69d47929f5b0e74579ab
sha256: f7f356f100aa04dcdb567a87351d175095fd68ad66400f26f0fcc42b56d854fa
sha512: fa3e363881fdc5bc72f25443341afb9dd4d52c7acc5e3a7331a85fe6c1a8c8240a0450e45a0fc51032ef8e4b18e40c1b5e7949e9febb8a720136f24e46e8e31a
ssdeep: 6144:TnK9TBS7DvZGfXo42F4+5cyIWZ94VZqlQT0OcQXZCR0uU5zx:TnK9TwH4flK4lM0Zz0OcQXZhuczx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10B44BF12F9C414F6DEB3347189EA6B36EAFBE918021899C3D7D49FC54850392762C78E
sha3_384: ab529667d37ac35abb3736eb6ddf083a7a7348ada2913700ecc4aadc7dbade68ae7de92585e749fc48e1aec75ebc95a0
ep_bytes: 558bec51535633f633c946e880f5ffff
timestamp: 2013-03-15 18:17:58

Version Info:

0: [No Data]

Kazy.55566 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Zbot.l!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Kazy.55566
FireEyeGeneric.mg.7d8c597a948e98f7
CAT-QuickHealTrojan.Generic.5979
ALYacGen:Variant.Kazy.55566
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.199793
SangforTrojan.Win32.Save.a
K7AntiVirusSpyware ( 004b8cd91 )
AlibabaTrojanSpy:Win32/FakeAlert.f753937c
K7GWSpyware ( 004b8cd91 )
Cybereasonmalicious.a948e9
BitDefenderThetaGen:NN.ZexaF.34212.qmX@a8KUtQm
VirITTrojan.Win32.Generic.CHNM
CyrenW32/FakeAlert.FY.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Zbot.AAU
TrendMicro-HouseCallCryp_Xin1
Paloaltogeneric.ml
ClamAVWin.Spyware.Zbot-1275
KasperskyTrojan-Spy.Win32.Zbot.jugj
BitDefenderGen:Variant.Kazy.55566
NANO-AntivirusTrojan.Win32.Zbot.bqobge
SUPERAntiSpywareTrojan.Agent/Gen-Zbot
APEXMalicious
TencentTrojan.Win32.Zbot.aaw
Ad-AwareGen:Variant.Kazy.55566
EmsisoftGen:Variant.Kazy.55566 (B)
ComodoTrojWare.Win32.Spy.ZBot.AAU@4wkkp5
DrWebTrojan.PWS.Panda.5676
VIPRETrojan.Win32.Zbot.aka (v)
TrendMicroCryp_Xin1
McAfee-GW-EditionBehavesLike.Win32.ZBot.dh
SophosML/PE-A + Mal/Behav-010
IkarusTrojan-PWS.Win32.Zbot
GDataGen:Variant.Kazy.55566
JiangminTrojanSpy.Zbot.cxlx
WebrootW32.Infostealer.Zeus
AviraTR/Spy.Gen
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASMalwS.12D446
ZoneAlarmTrojan-Spy.Win32.Zbot.jugj
MicrosoftPWS:Win32/Zbot!GO
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win32.Zbot.R57873
Acronissuspicious
McAfeePWS-Zbot.gen.apr
TACHYONTrojan-Spy/W32.ZBot.274432.AJ
VBA32BScope.Trojan.Zbot.6713
MalwarebytesMalware.AI.1559019732
RisingRansom.Satan!1.AEB7 (RDMK:cmRtazqeuOWVWlpWgXNfYdPD6UWg)
YandexTrojan.GenAsa!rPRUa+oLIso
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Zbot.AAU!tr
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Kazy.55566?

Kazy.55566 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment