Malware

About “Lazy.107211 (B)” infection

Malware Removal

The Lazy.107211 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.107211 (B) virus can do?

  • Dynamic (imported) function loading detected
  • .NET file is packed/obfuscated with Confuser
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Lazy.107211 (B)?


File Info:

name: 55C46A211512BE7F1798.mlw
path: /opt/CAPEv2/storage/binaries/89bd48742e2d8a2b896eb1cf02730c2c052654077fb01729b6aa9b6dd4852f2f
crc32: FA0C465E
md5: 55c46a211512be7f1798ff897087ed17
sha1: 26071674ba4ae47ea55041e7312bdbc72215148d
sha256: 89bd48742e2d8a2b896eb1cf02730c2c052654077fb01729b6aa9b6dd4852f2f
sha512: b4faf3c515c297f2fd5f126f54b16b67f5cba86320b6c54aeaeb103d6af9f50ea2aa5d77ac32534f5d26460bac58faa4e782a58ea8df7312a683013beb4c5ffa
ssdeep: 3072:7CfAvt3ftf6Uwc0h9M2Xp5pJ/X2vQO9vsrCLO2:eovtkBcm5zRrCi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12EC3E144BD5C5826E7190ABCA65FCA4ED6F65E201A06D78BF84CB29D4F323E5100673F
sha3_384: 458ee540750b20d5766f1ae9968aaf4c1d659f7cc094fbad0c48148468edfb39d03494e7758689716d18a146f0b6f607
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-02-01 20:41:13

Version Info:

Translation: 0x0000 0x04b0
Comments: Neton
CompanyName: Neton
FileDescription: Neton
FileVersion: 1.0.0.0
InternalName: Neton.exe
LegalCopyright: Neton
LegalTrademarks: Neton
OriginalFilename: Neton.exe
ProductName: Neton
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Lazy.107211 (B) also known as:

LionicTrojan.Win32.Banload.a!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.107211
FireEyeGeneric.mg.55c46a211512be7f
McAfeeRDN/Generic.dx
CylanceUnsafe
SangforTrojan.Win32.Banload.aboun
K7AntiVirusHacktool ( 0058e06f1 )
AlibabaTrojanDownloader:Win32/Banload.cdf2e00a
K7GWHacktool ( 0058e06f1 )
Cybereasonmalicious.4ba4ae
CyrenW32/MSIL_Kryptik.CRK.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/HackTool.Agent.RJ
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Downloader.Win32.Banload.aboun
BitDefenderGen:Variant.Lazy.107211
AvastFileRepMalware
TencentWin32.Trojan-downloader.Banload.Sxeq
Ad-AwareGen:Variant.Lazy.107211
EmsisoftGen:Variant.Lazy.107211 (B)
TrendMicroTROJ_GEN.R002C0PB822
McAfee-GW-EditionRDN/Generic.dx
SophosMal/Generic-S
GDataGen:Variant.Lazy.107211
eGambitUnsafe.AI_Score_99%
AviraTR/Hacktool.hcfxn
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Lazy.D1A2CB
ZoneAlarmTrojan-Downloader.Win32.Banload.aboun
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 99)
AhnLab-V3Malware/Win.Malware-gen.C4928092
BitDefenderThetaGen:NN.ZemsilF.34212.hm0@aeRERS
ALYacGen:Variant.Lazy.107211
MAXmalware (ai score=85)
VBA32TScope.Trojan.MSIL
MalwarebytesMalware.AI.906049620
TrendMicro-HouseCallTROJ_GEN.R002C0PB822
RisingMalware.Obfus/MSIL@AI.100 (RDM.MSIL:e0pwoAgtMIhD0TJoNUY+Hw)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.RJ!tr
AVGFileRepMalware
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Lazy.107211 (B)?

Lazy.107211 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment