Malware

About “Kazy.776890” infection

Malware Removal

The Kazy.776890 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Kazy.776890 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Macedonian
  • Looks up the external IP address
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to delete volume shadow copies
  • Exhibits behavior characteristic of Alphacrypt/Teslacrypt ransomware
  • Modifies boot configuration settings
  • Writes a potential ransom message to disk
  • Attempts to identify installed AV products by registry key
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Creates a known TeslaCrypt/AlphaCrypt ransomware decryption instruction / key file.
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

myexternalip.com

How to determine Kazy.776890?


File Info:

crc32: 9B17A057
md5: 1889dc06ddb66e11e48460ee23e02610
name: 1889DC06DDB66E11E48460EE23E02610.mlw
sha1: fce1ee5e59a4b388174f38988623f4b345d67c51
sha256: 66c21c8caf1f1061c83dd814246fc4f7465519398939b414d217c9f8ce63902b
sha512: 7eda6bc8bf4409174d86a55e93925d56bee23b6acfebf5a377aa1d66ce9c044e181ee429941a78bcbb6844949c9fd3cc97b60d4afde76493a0ecd3a960a67d3c
ssdeep: 6144:ubgOChJ7IM+hbIUJLA+bySUCC0Q90LHlZ9kam1m8dYMFx9RUC:ubg37IuUjKcF7Pm1fnpRUC
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Prized (C) 2010
InternalName: Organists
FileDescription: Lunches
OriginalFilename: Name.exe
CompanyName: Canon Information Systems, Inc.

Kazy.776890 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Kazy.776890
CAT-QuickHealRansom.Teslacrypt.D4
ALYacGen:Variant.Kazy.776890
CylanceUnsafe
VIPREWin32.Malware!Drop
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0055e3991 )
BitDefenderGen:Variant.Kazy.776890
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.6ddb66
BaiduWin32.Trojan.Filecoder.k
SymantecRansom.TeslaCrypt!g1
APEXMalicious
AvastWin32:TeslaCrypt-AL [Trj]
ClamAVWin.Virus.TeslaCrypt3-1
KasperskyTrojan.Win32.Yakes.nptm
NANO-AntivirusTrojan.Win32.Encoder.dyzazu
ViRobotTrojan.Win32.TeslaCrypt.Gen.B
AegisLabTrojan.Win32.Yakes.4!c
RisingTrojan.Ransom-Tesla!1.A322 (CLOUD)
Ad-AwareGen:Variant.Kazy.776890
EmsisoftGen:Variant.Kazy.776890 (B)
F-SecureHeuristic.HEUR/AGEN.1123567
DrWebTrojan.Encoder.3075
ZillyaTrojan.Injector.Win32.339510
TrendMicroRansom_CRYPTESLA.SM
McAfee-GW-EditionGenericR-FGD!1889DC06DDB6
FireEyeGeneric.mg.1889dc06ddb66e11
SophosML/PE-A + Mal/Tinba-Y
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Yakes.dtt
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1123567
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.TSGeneric
KingsoftWin32.Troj.Yakes.np.(kcloud)
MicrosoftVirTool:Win32/CeeInject.gen!E
ArcabitTrojan.Kazy.DBDABA
ZoneAlarmTrojan.Win32.Yakes.nptm
GDataGen:Variant.Kazy.776890
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Teslacrypt.R169477
Acronissuspicious
McAfeeGenericR-FGD!1889DC06DDB6
TACHYONTrojan/W32.Yakes.319488.L
VBA32BScope.Trojan.Inject
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.CNJW
TrendMicro-HouseCallRansom_CRYPTESLA.SM
TencentMalware.Win32.Gencirc.114c4f5b
YandexTrojan.Injector!8sbd7fXcELs
IkarusTrojan.Win32.Injector
eGambitUnsafe.AI_Score_100%
FortinetW32/Injector.CNRF!tr
BitDefenderThetaGen:NN.ZexaF.34590.tq0@aGZpVglG
AVGWin32:TeslaCrypt-AL [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.CeeInject.HgIASOkA

How to remove Kazy.776890?

Kazy.776890 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment