Adware

Adware.Lazy.673 removal

Malware Removal

The Adware.Lazy.673 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Lazy.673 virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Adware.Lazy.673?


File Info:

name: FD88976ABA9A5B390E0D.mlw
path: /opt/CAPEv2/storage/binaries/491fea2d3329534c6bee3afebe90cc975cf770b0fc7d3753bfcfd1bbe0675aa9
crc32: A5F7F5D0
md5: fd88976aba9a5b390e0dc1e630b69bd9
sha1: 0a2974b8f687ca683c1027b9ae0f7618bec0b3d0
sha256: 491fea2d3329534c6bee3afebe90cc975cf770b0fc7d3753bfcfd1bbe0675aa9
sha512: 363a7becad04b609799c2112e666d6954a3c2e4b05d08e0f7fa99d2dc667e0a41fecf04f9fbab512be82e7642eb82a53bb3cdb753b5d3f236ac6225c61521890
ssdeep: 6144:uGCFdhEITMK3iICM63nL9RDllyjK6XSzk9fyA4pEn:uGCFohK3D4nLHJlyjK6XX1yA6En
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1AC745950D6010336F9BE01F9C7BC1B9EE59C8A7A434954C7CBC8C87A58C6BE7AA34197
sha3_384: 3471135bb14043705dcdfaa43502ddf33cfce2c47b2192786320d16a580c99a0106c6a9ac73c0bc6a212a8616ba384a6
ep_bytes: 558bec83ec08a1106004108945fc8b4d
timestamp: 2012-01-12 13:44:48

Version Info:

CompanyName: SafeSvc
FileDescription: SafeSvc
FileVersion: 1.0.0.1
InternalName: SafeSvc.exe
LegalCopyright: Copyright (C) 2011
OriginalFilename: SafeSvc.exe
ProductName: SafeSvc
ProductVersion: 1.0.0.1
Translation: 0x0409 0x04b0

Adware.Lazy.673 also known as:

LionicTrojan.Win32.Generic.lvYv
SkyhighBehavesLike.Win32.MultiPlug.fh
ALYacGen:Variant.Adware.Lazy.673
Cylanceunsafe
VIPREGen:Variant.Adware.Lazy.673
SangforTrojan.Win32.Kazy.546221
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderGen:Variant.Adware.Lazy.673
ArcabitTrojan.Adware.Lazy.673
BitDefenderThetaGen:NN.ZedlaF.36802.vu8@amDsncab
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Korplug.I
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Korplug.c5d641ef
NANO-AntivirusTrojan.Win32.Tvt.owamp
MicroWorld-eScanGen:Variant.Adware.Lazy.673
AvastWin32:TrojanX-gen [Trj]
RisingBackdoor.Sogu!8.E650 (TFE:3:HkJXFlUp5AP)
EmsisoftGen:Variant.Adware.Lazy.673 (B)
F-SecureTrojan.TR/Kazy.546221
DrWebTrojan.KeyLogger.10921
ZillyaTrojan.Korplug.Win32.1753
FireEyeGeneric.mg.fd88976aba9a5b39
SophosMal/Generic-S
JiangminTrojan/Tvt.ag
GoogleDetected
AviraTR/Kazy.546221
MAXmalware (ai score=59)
Antiy-AVLTrojan/Win32.AGeneric
Kingsoftmalware.kb.a.946
XcitiumMalware@#1jl2m8p622rrz
MicrosoftTrojan:Win32/Ditertag.A
ViRobotTrojan.Win32.A.Tvt.345600
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Adware.Lazy.673
AhnLab-V3Backdoor/Win32.Etso.R17333
McAfeeArtemis!FD88976ABA9A
VBA32BScope.Trojan.Agent
PandaGeneric Malware
TencentWin32.Trojan.Kazy.Dnhl
YandexTrojan.Tvt!BV0agWQL/zU
IkarusTrojan-Downloader.Win32.Thoper
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Tvt.B!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Korplug.I

How to remove Adware.Lazy.673?

Adware.Lazy.673 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment