Malware

Kazy.76979 removal instruction

Malware Removal

The Kazy.76979 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Kazy.76979 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Serbian (Cyrillic)
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Kazy.76979?


File Info:

crc32: EFE541B4
md5: 79885853dcbd261bc977fed054092a78
name: 79885853DCBD261BC977FED054092A78.mlw
sha1: ca0c249e1dd0f7529d5c2aa6236e4958ed7c2720
sha256: d3c192a99ab3fda3a25547449de6efd58d68edce5d55fae6409c680cad24c1f4
sha512: c1f02189b51e000fef1fd05c6b17239847a4e02490afd231d8b7e372f0282a6576ba0e27348537125a58ba568701ea58f8af361800c638de770e6bd1bd9ae430
ssdeep: 1536:3J2oYqFO9sCHwqx39EsZsYpRLgyYIG9szU24QXWlo27hwomz:+mCHlSYpR8Ld2C2
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: bordi iride lisca 2010
InternalName: sviare
FileVersion: 8.02.0005
CompanyName: cedute vizia
LegalTrademarks: dannai gioivi
Comments: Py voluto poggio
ProductName: piogge
ProductVersion: 8.02.0005
FileDescription: Esulto forato timore gb
OriginalFilename: sviare.exe

Kazy.76979 also known as:

BkavW32.AIDetect.malware1
LionicWorm.Win32.Palevo.r!c
Elasticmalicious (high confidence)
DrWebTrojan.Matsnu.11
McAfeeGeneric.dx!79885853DCBD
CylanceUnsafe
ZillyaWorm.Palevo.Win32.83831
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Blocker.07f0378e
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Trustezeb.C
APEXMalicious
AvastWin32:Trojan-gen
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Blocker.fofs
BitDefenderGen:Variant.Kazy.76979
NANO-AntivirusTrojan.Win32.Matsnu.tisyr
ViRobotWorm.Win32.A.P2P-Palevo.98304.AD
MicroWorld-eScanGen:Variant.Kazy.76979
TencentWin32.Trojan.Blocker.Ajca
Ad-AwareGen:Variant.Kazy.76979
SophosML/PE-A + Troj/Ransom-GW
ComodoTrojWare.Win32.Injector.XFR@4rorse
BitDefenderThetaGen:NN.ZevbaF.34142.gm0@a8g@ehiG
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.nm
FireEyeGeneric.mg.79885853dcbd261b
EmsisoftGen:Variant.Kazy.76979 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Blocker.bfy
WebrootW32.Trojan.Agent.Gen
AviraTR/Ransom.EK.1
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.1626C8
KingsoftWin32.Troj.Generic.(kcloud)
MicrosoftTrojan:Win32/Matsnu
ArcabitTrojan.Kazy.D12CB3
ZoneAlarmTrojan-Ransom.Win32.Blocker.fofs
GDataGen:Variant.Kazy.76979
VBA32BScope.TrojanSpy.Zbot
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Ransom.AB
YandexTrojan.GenAsa!E1hcZucXXh8
IkarusTrojan.Jorik
MaxSecureTrojan.Malware.4162294.susgen
FortinetW32/VBKrypt.MBSX!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Kazy.76979?

Kazy.76979 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment