Malware

About “Kazy.88852” infection

Malware Removal

The Kazy.88852 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Kazy.88852 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid

How to determine Kazy.88852?


File Info:

name: B2152C92B1427B28AB87.mlw
path: /opt/CAPEv2/storage/binaries/adbd8a68422648cae5df2ae90edc2ae2204b5da932e9933e6a6f3e90490db42c
crc32: C7A8A340
md5: b2152c92b1427b28ab8789a37667f80c
sha1: e6b9ea959b73061be11850d1010e8b92c6ad51d6
sha256: adbd8a68422648cae5df2ae90edc2ae2204b5da932e9933e6a6f3e90490db42c
sha512: e06114090dbed623713051807179ad43cac915d4f1981d99c9071ebb0c946b39fe5f4294db87acfffbb737e5383627705beaaa0a98395d8e186cfffa2d615b55
ssdeep: 3072:sMK5zTjwJAGHPurIWwTJI0j+xunMzC+0pdQAGJNuu9L1MOo8a:EzTjwahIWoJI0jln4ku9M
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1894577F5620D6E03A26BDA27EE2C4D21CF286144E37D55A6C4A4FDCB0B43DFE9618613
sha3_384: 305cc6e35c08fa6b42c46324878235f118141b16c2ec862cd78fd54b5f7ca7062a73b983a5b536330a200458793a7e21
ep_bytes: 558bec83c4a003f12bc2f7d7f7da43be
timestamp: 2008-08-25 00:28:30

Version Info:

CompanyName: Mdwcv Drxkfhen
FileDescription: Mdwcv Wkpfuuetsb Evglnlbywp
FileVersion: 73, 98, 66, 107
InternalName: Mdwcv
LegalCopyright: Copyright © Mdwcv Drxkfhen 1998-2008
OriginalFilename: Mdwcv.exe
ProductName: Mdwcv Wkpfuuetsb Evglnlbywp
ProductVersion: 93, 103, 80, 74
Translation: 0x0409 0x04e4

Kazy.88852 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Zbot.l!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Kazy.88852
FireEyeGeneric.mg.b2152c92b1427b28
ALYacGen:Variant.Kazy.88852
CylanceUnsafe
VIPRETrojan.Win32.Kryptik.mcf (v)
SangforSpyware.Win32.Zbot.YW
K7AntiVirusSpyware ( 0055e3db1 )
AlibabaTrojanSpy:Win32/Spyeye.b0fd9bbf
K7GWSpyware ( 0055e3db1 )
Cybereasonmalicious.2b1427
VirITBackdoor.Win32.Qbot.DD
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Zbot.YW
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Spy.Win32.Zbot.bgoc
BitDefenderGen:Variant.Kazy.88852
NANO-AntivirusTrojan.Win32.Zbot.eclzuu
SUPERAntiSpywareHeur.Agent/Gen-StaticIcon
AvastWin32:MalOb-FS [Cryp]
RisingSpyware.Zbot!8.16B (CLOUD)
Ad-AwareGen:Variant.Kazy.88852
EmsisoftGen:Variant.Kazy.88852 (B)
ComodoMalware@#2hzalqmnddxdk
DrWebBackDoor.Qbot.81
ZillyaTrojan.Zbot.Win32.207464
McAfee-GW-EditionPWS-Zbot.gen.fw
SophosMal/Generic-R + Troj/Zbot-ANH
IkarusNet-Worm.Win32.Kolab
GDataGen:Variant.Kazy.88852
JiangminTrojanSpy.Zbot.awwj
AviraTR/Spy.Zbot.asuf
Antiy-AVLTrojan/Generic.ASMalwS.18937C6
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftPWS:Win32/Zbot!ZA
CynetMalicious (score: 100)
McAfeePWS-Zbot.gen.fw
MAXmalware (ai score=99)
VBA32Trojan.Zeus.EA.0999
TencentMalware.Win32.Gencirc.114be9f2
YandexTrojanSpy.Zbot!AZS+QZbwf40
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.1749544.susgen
FortinetW32/PackFakeAV.JX!tr
BitDefenderThetaGen:NN.ZexaF.34212.jr1@auuYVxec
AVGWin32:MalOb-FS [Cryp]
PandaBck/Qbot.AO
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Kazy.88852?

Kazy.88852 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment