Malware

Lazy.188855 removal guide

Malware Removal

The Lazy.188855 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.188855 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Lazy.188855?


File Info:

name: 0414ACA08D3D3A3A9797.mlw
path: /opt/CAPEv2/storage/binaries/20d872857fa9d5497e4113220412b72e8d64e17667305d19f37bf77e7cdfff00
crc32: 3D3DB23A
md5: 0414aca08d3d3a3a9797374f0b9849d1
sha1: 24fd3424d5a9258a55c92bbc406a76ba3bcf4a87
sha256: 20d872857fa9d5497e4113220412b72e8d64e17667305d19f37bf77e7cdfff00
sha512: ef4ea83e42a62297d7115778e75754df57074bdbc1e68920336f36fd257b09fd5a6947838c7b07183819b23b0d972c62872965a24df5aabcebdd06e4f0b5bb1a
ssdeep: 3072:Ov6nJj/UW1KmZqiyzf1QnhW2IF2B2Tj3Zj:OyJj/siyZQhW1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A6E3E0439B2C80B3D862433CAC4E93D2E571B2643E8E84569B13366EF42EDF56714F96
sha3_384: 72fe956ad3e448d361f00e3fe417d70647a53a8acb2ed154638236d1653d6df52bf4356ec8aeeb295f011a1929ad3806
ep_bytes: b9ed8543008b0109c0894914a1348743
timestamp: 2009-07-01 18:18:02

Version Info:

Comments:
CompanyName: Simon Tatham
FileDescription: KLitek Setup
FileVersion: 3.0.0.111
InternalName: literm.exe
LegalCopyright: Copyright © 2009 Simon TathamR All rights reserved.Hi
LegalTrademarks:
OriginalFilename: literm.exe
ProductName: II
ProductVersion: 3.0.0.111
Translation: 0x0409 0x04e4

Lazy.188855 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.188855
ClamAVWin.Trojan.Agent-524927
CAT-QuickHealTrojan.Renos.LN
ALYacGen:Variant.Lazy.188855
MalwarebytesCrypt.Trojan.Malicious.DDS
VIPREGen:Variant.Lazy.188855
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005485311 )
AlibabaTrojan:Win32/FlashApp.bb66457c
K7GWTrojan ( 005485311 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36318.jy0@aGxcENfk
VirITTrojan.Win32.Dnldr1.BWGC
CyrenW32/Downloader.CO.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.OLL
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Hoax.Win32.FlashApp.a
BitDefenderGen:Variant.Lazy.188855
NANO-AntivirusTrojan.Win32.Dwn.dfkta
AvastWin32:Renos-AOZ [Trj]
TencentMalware.Win32.Gencirc.114d6c43
EmsisoftGen:Variant.Lazy.188855 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen3
DrWebTrojan.DownLoader1.32606
ZillyaTrojan.FakeAV.Win32.80164
TrendMicroTROJ_RENOS.SM10
McAfee-GW-EditionDownloader-CEW.au
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.0414aca08d3d3a3a
SophosMal/FakeAV-IZ
SentinelOneStatic AI – Malicious PE
WebrootTrojan.Win32.Hiloti
AviraTR/Crypt.XPACK.Gen3
Antiy-AVLHackTool[Hoax]/Win32.FlashApp
MicrosoftTrojanDownloader:Win32/Renos.PT
XcitiumTrojWare.Win32.Kryptik.NMH@40ezx9
ArcabitTrojan.Lazy.D2E1B7
ZoneAlarmHEUR:Hoax.Win32.FlashApp.a
GDataGen:Variant.Lazy.188855
GoogleDetected
AhnLab-V3Trojan/Win32.FakeAV.R4714
McAfeeDownloader-CEW.au
MAXmalware (ai score=100)
VBA32Trojan.MSA.1215
Cylanceunsafe
PandaTrj/FakeST.A
TrendMicro-HouseCallTROJ_RENOS.SM10
RisingDownloader.Renos!8.1D0 (TFE:1:L75Do7LnN5U)
YandexTrojan.DL.Renos!vZs/wOIrfSM
IkarusTrojan-Downloader.SuspectCRC
MaxSecureTrojan.Malware.2588.susgen
FortinetW32/Krypt.QKV!tr
AVGWin32:Renos-AOZ [Trj]
DeepInstinctMALICIOUS

How to remove Lazy.188855?

Lazy.188855 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment