Adware

How to remove “Adware.Lazy.804”?

Malware Removal

The Adware.Lazy.804 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Lazy.804 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Adware.Lazy.804?


File Info:

name: 009648F87F928B9C8C3A.mlw
path: /opt/CAPEv2/storage/binaries/df5d75358476d6a35b00dfa4c0476dbe0349646b97a913e33a6b671c79bdf159
crc32: 17CF970D
md5: 009648f87f928b9c8c3a63cd71b6fb19
sha1: 67ec5d5686a94faf4e70cc83f5908dea33997030
sha256: df5d75358476d6a35b00dfa4c0476dbe0349646b97a913e33a6b671c79bdf159
sha512: b6c3051cb83bd46a470f598d799289e3e884ca31c52a5f7af937c5bb6c444fb2bb1f66ee3b9346cc6319f9dc43c334d209100c354ae7dc61dca07f2cb1b682d0
ssdeep: 12288:9FM6jRC9YluAkRJPeO3vi115BynxFvJbsP:PjI9FJeOgebK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D8C41291E5F87F92E09F0579046BE6C5C76BBE00A32450EE767F392338360920B69F25
sha3_384: 24227ce1329caf78adc0b4329c62b1fe236fc8123befa317d6ef738e29d90272d779b943473fbec52604f3f73c4802c0
ep_bytes: e9376c070083f9ff7d09c605af904700
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: Microsoft Corporation
FileDescription: XmlHttp Soap Connector Library
FileVersion: 1.02.813.0
InternalName: XHSC10
LegalCopyright: © 1988-2000 Microsoft Corp. All rights reserved.
LegalTrademarks: Microsoft(R) is a registered trademark of Microsoft Corporation. Windows (R) is a registered trademark of Microsoft Corporation.
OriginalFilename: XHSC10.dll
ProductName: Microsoft Soap SDK
ProductVersion: 1.02.813.0
OLESelfRegister:
Translation: 0x0409 0x04e4

Adware.Lazy.804 also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Adware.Lazy.804
ClamAVWin.Adware.Agent-1377746
CAT-QuickHealTrojan.Sisproc.A6
McAfeePacked-CQ
MalwarebytesLoadMoney.Adware.Bundler.DDS
ZillyaAdware.LoadMoneyGen.Win32.8
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0040f8391 )
AlibabaDownloader:Win32/Plocust.45c20c3f
K7GWTrojan ( 0040f8391 )
Cybereasonmalicious.87f928
BaiduWin32.Adware.Kryptik.c
CyrenW32/Threat-SysVenFak-based!Maxi
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Adware.LoadMoney.OQ
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:HEUR:Downloader.Win32.Plocust.heur
BitDefenderGen:Variant.Adware.Lazy.804
NANO-AntivirusTrojan.Win32.Plocust.ddhoxc
AvastWin32:LoadMoney-APM [Adw]
TencentMalware.Win32.Gencirc.13aff0db
EmsisoftGen:Variant.Adware.Lazy.804 (B)
F-SecureAdware.ADWARE/WebAlta.qoys
DrWebTrojan.LoadMoney.225
VIPREGen:Variant.Adware.Lazy.804
TrendMicroTROJ_OGIMANT.SMA
McAfee-GW-EditionBehavesLike.Win32.Dropper.hh
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.009648f87f928b9c
SophosApp/Generic-GH (PUA)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Adware.Lazy.804
JiangminDownloader.Plocust.ns
AviraADWARE/WebAlta.qoys
MAXmalware (ai score=100)
Antiy-AVLRiskWare[Downloader]/Win32.Plocust
XcitiumTrojWare.Win32.Kryptik.CHGJ@5dj2h9
ArcabitTrojan.Adware.Lazy.804
ZoneAlarmnot-a-virus:HEUR:Downloader.Win32.Plocust.heur
MicrosoftTrojan:Win32/Dorv.B!rfn
GoogleDetected
AhnLab-V3Adware/Win32.LoadMoney.R115803
BitDefenderThetaGen:NN.ZexaF.36318.Hy0@a8F3Wfek
ALYacGen:Variant.Adware.Lazy.804
VBA32BScope.TrojanSpy.Zbot.2712
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_OGIMANT.SMA
RisingAdware.LoadMoney!1.B21E (CLASSIC)
YandexTrojan.GenAsa!sQ0lf7Ojems
IkarusVirus.Win32.Cryptor
FortinetRiskware/LMN
AVGWin32:LoadMoney-APM [Adw]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Adware.Lazy.804?

Adware.Lazy.804 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment