Malware

Kazy.6214 removal

Malware Removal

The Kazy.6214 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Kazy.6214 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Installs an hook procedure to monitor for mouse events
  • Sniffs keystrokes
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Kazy.6214?


File Info:

crc32: 21280BCC
md5: 1971571923037cc0a060d17f3b53c357
name: 1971571923037CC0A060D17F3B53C357.mlw
sha1: 3f871ddd05ab6aa286f062eba61e73a741d09b50
sha256: a1b39a791f658c21a42abc8fd07b277d6b66a6a06998c55b79c88e895917cdda
sha512: 3cd6edc98d7515eb045e191b2681406e468f3aa9a42645cb35952b54cef905cdf81e85088fdf37c5ceae03443abd8ae9285772fcc67e5d68c1c03979b4755dfd
ssdeep: 1536:71+qd1YMcvWd1DJtH6TcduMuRo1GuDLYFs2P2SwR3lkzzgktU0THtYvsBwME:J+qd20BbaTHRmfY6JlkYke07tVBw
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: TeamViewer GmbH
InternalName: TeamViewer
FileVersion: 6.0.9895.0
CompanyName: TeamViewer GmbH
PrivateBuild: TeamViewer Remote Control Application
LegalTrademarks: TeamViewer
ProductName: TeamViewer
ProductVersion: 6.0
FileDescription: TeamViewer Remote Control Application
OriginalFilename: TeamViewer.exe
Translation: 0x0809 0x04b0

Kazy.6214 also known as:

K7AntiVirusTrojan ( 0055dd191 )
DrWebTrojan.Packed.21425
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Yakes
ALYacGen:Variant.Kazy.6214
CylanceUnsafe
ZillyaTrojan.HmBlocker.Win32.667
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/LockScreen.ba699248
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.923037
CyrenW32/S-b8cdf7ec!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.LKI
APEXMalicious
AvastWin32:Crypt-ISX [Drp]
ClamAVWin.Trojan.Hmblocker-721
KasperskyUDS:Trojan.Win32.Yakes.sb
BitDefenderGen:Variant.Kazy.6214
NANO-AntivirusTrojan.Win32.Winlock.dcszu
ViRobotTrojan.Win32.A.HmBlocker.88576
MicroWorld-eScanGen:Variant.Kazy.6214
TencentWin32.Trojan.Hmblocker.Dzaf
Ad-AwareGen:Variant.Kazy.6214
ComodoMalware@#tc0ue8p6vfok
BitDefenderThetaGen:NN.ZexaF.34722.fu0@aCR8TydG
VIPRETrojan.Win32.FakeAV.gq (v)
TrendMicroRansom_LockScreen.R002C0DEU21
McAfee-GW-EditionStymic
FireEyeGeneric.mg.1971571923037cc0
EmsisoftGen:Variant.Kazy.6214 (B)
JiangminTrojan/HmBlocker.bmw
WebrootW32.Malware.Gen
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.7CFAD4
MicrosoftRansom:Win32/LockScreen.BR
ArcabitTrojan.Kazy.D1846
AegisLabTrojan.Win32.HmBlocker.j!c
GDataGen:Variant.Kazy.6214
AhnLab-V3Spyware/Win32.Zbot.R24793
McAfeeStymic
MAXmalware (ai score=100)
VBA32Trojan.ExpProc.014
MalwarebytesTrojan.Agent
PandaGeneric Malware
TrendMicro-HouseCallRansom_LockScreen.R002C0DEU21
RisingTrojan.Generic@ML.94 (RDML:GabFEsMx3fQLldGg7hKzMQ)
YandexTrojan.HmBlocker!9TD0A8BM3cs
IkarusTrojan-Ransom.HmBlocker
FortinetW32/Yakes.S!tr
AVGWin32:Crypt-ISX [Drp]
Paloaltogeneric.ml

How to remove Kazy.6214?

Kazy.6214 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment