Malware

Kazy.56153 removal

Malware Removal

The Kazy.56153 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Kazy.56153 virus can do?

  • At least one process apparently crashed during execution
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Kazy.56153?


File Info:

name: CF3BF5FA0A7C73805A54.mlw
path: /opt/CAPEv2/storage/binaries/bbbbf151a0c301679bc75d902b8653b3cd684d6acc914df76de799d977ad1493
crc32: CB37255C
md5: cf3bf5fa0a7c73805a54467de05c29b8
sha1: b1d31033bcfafcbdeef8d52da422f3c10f70e7be
sha256: bbbbf151a0c301679bc75d902b8653b3cd684d6acc914df76de799d977ad1493
sha512: 4567888764f160f3eb0ccdab8aa76406d0e72ada174444837f2e1539d1a5b9f51199d6d15fcfe16fd8b1a63632c3cd39df8efe938ab2f97f1899e4bccff6c793
ssdeep: 6144:bsCBYUeDZOIsaa1+oBM6/2o3EwwQBlJl4LwQ9kvFDZ576RzWB9XV7DoSQ:bseYvZOIXdoBJ/2oUlmJl4LwRNCRzq5Q
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A7742A22E053EC4FE91B9C7C52538C1982DE63B58F26172F6BF8551ED22AF50E8A0717
sha3_384: dd2baa4377fbca4474cb49d6aaf1c6d8d5ecf8c1f701f74605045f332e8fd94c6b0052725653e0efa59349ffbb4a6c15
ep_bytes: e88c01feffe913ffffff000000000000
timestamp: 2011-01-03 10:31:16

Version Info:

CompanyName: Quick Heal Technologies (P) Ltd.
FileDescription: Quick Heal AntiMalware
FileVersion: 6.0.0.1
InternalName: asmain.exe
LegalCopyright: © Quick Heal Technologies (P) Ltd. All rights reserved.
OriginalFilename: asmain.exe
ProductName: Quick Heal AntiVirus
ProductVersion: 13.00
Translation: 0x0409 0x04e4

Kazy.56153 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Kazy.56153
FireEyeGeneric.mg.cf3bf5fa0a7c7380
ALYacGen:Variant.Kazy.56153
CylanceUnsafe
VIPRETrojan.Win32.Reveto.D (v)
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
AlibabaTrojanSpy:Win32/EncPk.5c5910be
K7GWTrojan ( 004bcce41 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Zbot.DP.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Zbot.YW
APEXMalicious
ClamAVWin.Trojan.Reveton-4
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Kazy.56153
NANO-AntivirusTrojan.Win32.MlwGen.brkaeu
SUPERAntiSpywareTrojan.Agent/Gen-Crypt
AvastWin32:dUmPeX [Susp]
TencentMalware.Win32.Gencirc.116ecfaf
Ad-AwareGen:Variant.Kazy.56153
SophosMal/EncPk-ABFO
ComodoPacked.Win32.MUPX.Gen@24tbus
ZillyaTrojan.Menti.Win32.31328
McAfee-GW-EditionPWS-Zbot.gen.rd
EmsisoftGen:Variant.Kazy.56153 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Kazy.56153
JiangminTrojan/Generic.xbee
WebrootW32.Infostealer.Zeus
AviraTR/Spy.Zbot.YI.7
Antiy-AVLTrojan/Generic.ASMalwS.2BD56
KingsoftWin32.Troj.Undef.(kcloud)
ViRobotTrojan.Win32.Zbot.354304.C
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftPWS:Win32/Zbot!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Menti.R20280
Acronissuspicious
McAfeePWS-Zbot.gen.rd
MAXmalware (ai score=100)
VBA32BScope.Trojan.Skeeyah
MalwarebytesMalware.AI.744254185
RisingSpyware.Zbot!8.16B (CLOUD)
YandexTrojan.GenAsa!Me388YHOG10
IkarusWorm.Socks
MaxSecureTrojan.Malware.2588.susgen
FortinetW32/Kryptik.ABC!tr
BitDefenderThetaGen:NN.ZexaF.34212.vm1@ailYxFni
AVGWin32:dUmPeX [Susp]
Cybereasonmalicious.a0a7c7
PandaTrj/Genetic.gen

How to remove Kazy.56153?

Kazy.56153 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment