Malware

Lazy.333809 (B) removal guide

Malware Removal

The Lazy.333809 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.333809 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Collects information to fingerprint the system
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Lazy.333809 (B)?


File Info:

name: C53C7BADB34B61663220.mlw
path: /opt/CAPEv2/storage/binaries/0df2728a37e91486f75b620893bdc8dfd59bcc759bc6ce1fc1e8c5554c806c26
crc32: 33E36140
md5: c53c7badb34b61663220132da1987e40
sha1: 287d1d92676c790d1fb56b53d0d9502e0048253b
sha256: 0df2728a37e91486f75b620893bdc8dfd59bcc759bc6ce1fc1e8c5554c806c26
sha512: ca1b63acb81709b4ac3c906759100bb11de60d80ce7db69a7ad5a094cda4236647ffbc97ea72ef889946bee377240b0afe7a2f03d83985dbf0d3c295880806c6
ssdeep: 6144:9C0v3TTRGTeU94sbN/mzCbL02Nlxy6McevaycPl6yzh0H0xH9NDDOfHvAQ6AyLrx:9C0vBhU9biQY2Nlx7kuh0UxH9ND6fvhG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D77423B6C71BA38CDAE15F7322CD80CE9AC4555BC980B00508E3AC9C96735BDEE067D6
sha3_384: 2f838ba4468d6928fe4005a77331b8bcf120986318b394e64515750d81f5ff23853e0f701a49f4e8432e1a5631226d43
ep_bytes: 60be156043008dbeebaffcff57eb0b90
timestamp: 2013-08-20 04:52:20

Version Info:

CompanyName: Корпорация М айкрософт
FileDescription: Диспетчер синхронизации
FileVersion: 5.1.2600.5512 (xpsp.080413-2108)
Translation: 0x0419 0x04b0

Lazy.333809 (B) also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
DrWebTrojan.Mods.1
MicroWorld-eScanGen:Variant.Lazy.333809
McAfeeGenericRXHA-CF!5AFD2913A318
Cylanceunsafe
VIPREGen:Variant.Lazy.333809
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0051918e1 )
K7GWTrojan ( 0051918e1 )
Cybereasonmalicious.db34b6
BitDefenderThetaGen:NN.ZexaF.36196.wmNfai40q3lc
CyrenW32/Agent.BCI.gen!Eldorado
SymantecPacked.Generic.459
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.BIKE
APEXMalicious
ClamAVWin.Packed.Fugrafa-10002548-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Lazy.333809
NANO-AntivirusTrojan.Win32.ShipUp.cqkxsc
AvastWin32:Kryptik-MSQ [Trj]
TencentTrojan.Win32.Agent.afi
EmsisoftGen:Variant.Lazy.333809 (B)
F-SecureTrojan.TR/Kryptik.oenzy
BaiduWin32.Trojan.Kryptik.ac
ZillyaTrojan.Generic.Win32.923727
TrendMicroTROJ_KRYPTK.SML6
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.c53c7badb34b6166
SophosTroj/Agent-ADXT
IkarusTrojan.Win32.Krypt
GDataWin32.Trojan.Kryptik.PS
JiangminTrojan/ShipUp.vk
AviraTR/Kryptik.oenzy
Antiy-AVLTrojan/Win32.ShipUp.ebpa
XcitiumTrojWare.Win32.Kryptik.BHWB@50ugd2
ArcabitTrojan.Lazy.D517F1
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Vindor!pz
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Kryptik.R287817
VBA32Trojan.Redirect
ALYacGen:Variant.Lazy.333809
MAXmalware (ai score=87)
MalwarebytesMalware.AI.691983525
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_KRYPTK.SML6
RisingDropper.Gepys!8.15D (TFE:5:j8Xv8Jwh9WV)
YandexTrojan.GenAsa!PiNYPv4n41Y
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Zbot.FG!tr
AVGWin32:Kryptik-MSQ [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Lazy.333809 (B)?

Lazy.333809 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment