Malware

Lazy.106695 (file analysis)

Malware Removal

The Lazy.106695 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.106695 virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Lazy.106695?


File Info:

name: AB45FF8A6BA9851D1651.mlw
path: /opt/CAPEv2/storage/binaries/6e694371582df8a53a80be0ec03f092e52502b45cc7b4667f5ce4e4cd162f916
crc32: 7669C62D
md5: ab45ff8a6ba9851d1651e3e469bead37
sha1: 37a2cee189a2f0e18555991b14972e2b301fc2ed
sha256: 6e694371582df8a53a80be0ec03f092e52502b45cc7b4667f5ce4e4cd162f916
sha512: 2908608983c97672e7526140c03427d320cfcf20291871b6bad3c5e3c76fb6b2cc30fbbb6b03c3ed0cfcb68c22c5bf81b37f0a344d34b32660b8e07bf0ca30d3
ssdeep: 768:DDL9P9H8z/Ty6v2jjGPllAw9P9H8z/Ty6v2jjGPllAdAHzpaVRyuQ9P9H8z/Ty6A:DrcC6gjyrcC6gjyw8zDcC6gjyy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A383AE4C5347C735C93805311CBDDAE4195AB9CA8918736FFE7D3BB3A3023469A275A2
sha3_384: 1a18f6b0f2313a02ea29d2cc832417ad65990ee75617dfa4a13ba08672c751c959a21252947a1420374800379fabad9e
ep_bytes: ff2500204000fffefdfcfbfaaaaa0000
timestamp: 2098-09-21 23:51:31

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: GamePnPLauncher
FileVersion: 1.0.0.0
InternalName: GamePnPLauncher.exe
LegalCopyright: Copyright © 2021
LegalTrademarks:
OriginalFilename: GamePnPLauncher.exe
ProductName: GamePnPLauncher
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Lazy.106695 also known as:

BkavW32.AIDetectNet.01
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.106695
FireEyeGen:Variant.Lazy.106695
ALYacGen:Variant.Lazy.106695
VIPREGen:Variant.Lazy.106695
K7AntiVirusRiskware ( 00584baa1 )
K7GWRiskware ( 00584baa1 )
CrowdStrikewin/malicious_confidence_90% (W)
ArcabitTrojan.Lazy.D1A0C7
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Lazy.106695
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Lazy.106695
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1217181
ZillyaTrojan.Generic.Win32.1641891
McAfee-GW-EditionRDN/Generic.hbg
EmsisoftGen:Variant.Lazy.106695 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1217181
MicrosoftTrojan:Win32/Tiggre!rfn
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Lazy.106695
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4973108
Acronissuspicious
McAfeeRDN/Generic.hbg
MAXmalware (ai score=85)
VBA32Trojan.Sabsik.FL
CylanceUnsafe
IkarusTrojan.MSIL.Crypt
MaxSecureTrojan.Malware.7164915.susgen
FortinetMalicious_Behavior.SB
BitDefenderThetaGen:NN.ZemsilF.34742.fm0@aCoupTp
AVGWin32:Malware-gen
PandaTrj/GdSda.A

How to remove Lazy.106695?

Lazy.106695 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment