Malware

Kazy.81125 removal

Malware Removal

The Kazy.81125 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Kazy.81125 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Kazy.81125?


File Info:

crc32: 1A16E5A9
md5: 184d9c70bc5fa3a98c73c483b2c1710c
name: 184D9C70BC5FA3A98C73C483B2C1710C.mlw
sha1: 1975a3157b40750147cc2fd07682de1725636d8c
sha256: c728f19d54ce156fa96ba1929e1816a83ddf0c6bf31b8f7053c6fec950ac8ac5
sha512: dfcf9ac9ea4382ad8efdea325d2b530e37899b400aa41ce0b2968b986663a8eb910203214a8b934a15665b8dd752a5ed15e854d1f95d1d40f77073b3f90b6657
ssdeep: 3072:S5+Qp0TaVua9KhjXIrSocQ4/w2/kXH3nXH3nXH3:R/avYjXIrH
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright Razer 2004
InternalName: Exclusive Closures
FileVersion: 3.0.0
CompanyName: Razer
ProductName: Exclusive Closures
ProductVersion: 3.0.0
FileDescription: Exclusive Closures
OriginalFilename: exclusiveclosures.exe
Translation: 0x0809 0x04b0

Kazy.81125 also known as:

K7AntiVirusTrojan ( 0055dd191 )
LionicTrojan.Win32.Foreign.j!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen4.2054
CynetMalicious (score: 100)
ALYacGen:Variant.Kazy.81125
CylanceUnsafe
ZillyaTrojan.Foreign.Win32.1149
CrowdStrikewin/malicious_confidence_60% (D)
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.0bc5fa
CyrenW32/Falab.G.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.AILV
APEXMalicious
AvastWin32:Ransom-LI [Trj]
ClamAVWin.Trojan.Foreign-40
KasperskyTrojan-Ransom.Win32.Blocker.koac
BitDefenderGen:Variant.Kazy.81125
NANO-AntivirusTrojan.Win32.TrjGen.unkrv
ViRobotTrojan.Win32.A.Foreign.102400.G
MicroWorld-eScanGen:Variant.Kazy.81125
TencentWin32.Trojan.Foreign.jfh
Ad-AwareGen:Variant.Kazy.81125
SophosMal/NecursDrp-A
ComodoSuspicious@#zfe0oyc0hm7o
BitDefenderThetaGen:NN.ZexaF.34058.gu0@a4KNZnni
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_RANSOM.BSG
McAfee-GW-EditionGeneric.lx
FireEyeGeneric.mg.184d9c70bc5fa3a9
EmsisoftGen:Variant.Kazy.81125 (B)
JiangminTrojan/Foreign.aey
WebrootW32.Rogue.Gen
AviraTR/Crypt.XPACK.Gen7
Antiy-AVLTrojan/Generic.ASMalwS.2462B0
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Tobfy.A
ArcabitTrojan.Kazy.D13CE5
GDataGen:Variant.Kazy.81125
TACHYONTrojan/W32.Foreign.102400
AhnLab-V3Spyware/Win32.Zbot.C162311
McAfeeGeneric.lx
MAXmalware (ai score=89)
VBA32Hoax.Foreign
PandaGeneric Malware
TrendMicro-HouseCallTROJ_RANSOM.BSG
RisingTrojan.Generic@ML.100 (RDML:XEMDzBTbtbsCeiOlgXX8kQ)
IkarusTrojan-Ransom.Foreign
FortinetW32/Injector.FJFE!tr
AVGWin32:Ransom-LI [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HxQBEpsA

How to remove Kazy.81125?

Kazy.81125 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment