Malware

Lazy.111651 removal instruction

Malware Removal

The Lazy.111651 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.111651 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Lazy.111651?


File Info:

name: EED4694DBAC48F398C57.mlw
path: /opt/CAPEv2/storage/binaries/860dac19d19999f22d6a9b88a98e97d18f62921a3ee19e53ba89961bf999e82a
crc32: EE57898F
md5: eed4694dbac48f398c57411f6e86b462
sha1: 40b39320d1987a421c9f4d472bde5bd111aa6024
sha256: 860dac19d19999f22d6a9b88a98e97d18f62921a3ee19e53ba89961bf999e82a
sha512: cbd31accc79a14a265200c6c6f87b2bcf93016119c09c8580d23d7ef118b6f2d2424861cff97e370f33bfe4a01f908dcfe7ea03037b38c9c897bb4a242127d59
ssdeep: 6144:RN1vrAwzqEybL8e3iqLnFHgBua12BM6SZMIE7Uli+I/Up:jZAXJ8eRLKwo6MC7Uli+I/Up
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F154F0817A0C8FABD8742AB4005A572700ADB7CEBC5B815A5E9CA39DF43D4C949BF31C
sha3_384: fcc9699f766482b7e269448ea2df164ff5aef6016724d77782a28230f263ec1e244039eb8104aad225b115e53200cb49
ep_bytes: 558bec81eccc02000060892d647f4400
timestamp: 2012-04-10 18:24:05

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Windows Disk Diagnostic User Resolver
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
InternalName: DFDWiz.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: DFDWiz.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.1.7600.16385
Translation: 0x0409 0x04b0

Lazy.111651 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.lw2L
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.eed4694dbac48f39
CAT-QuickHealTrojanPWS.Zbot.Y
McAfeePWS-Zbot.gen.bew
MalwarebytesMalware.AI.1372763556
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0040f02a1 )
AlibabaVirTool:Win32/Obfuscator.ce0a957c
K7GWTrojan ( 0040f02a1 )
Cybereasonmalicious.dbac48
BaiduWin32.Adware.Kryptik.b
VirITTrojan.Win32.Banker.HM
CyrenW32/Zbot.DQ.gen!Eldorado
SymantecPacked.Generic.459
ESET-NOD32Win32/Spy.Zbot.AAN
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Zbot-1326
KasperskyPacked.Win32.Krap.iu
BitDefenderGen:Variant.Lazy.111651
NANO-AntivirusTrojan.Win32.Krap.brahfv
SUPERAntiSpywareTrojan.Agent/Gen-Zbot
MicroWorld-eScanGen:Variant.Lazy.111651
AvastWin32:Karagany
TencentWin32.Trojan.Spy.Apmq
Ad-AwareGen:Variant.Lazy.111651
SophosMal/Generic-R + Troj/Zbot-DHN
ComodoTrojWare.Win32.Kryptik.ADXK@4nyoqo
DrWebTrojan.PWS.Panda.2004
VIPRETrojan.Win32.Reveton.ca (v)
TrendMicroMal_Ransom-1
EmsisoftGen:Variant.Lazy.111651 (B)
IkarusTrojan-PWS.Win32.Zbot
GDataGen:Variant.Lazy.111651
JiangminTrojanSpy.Zbot.bpyw
WebrootW32.Rogue.Gen
AviraTR/Spy.Zbot.ZP.6
Antiy-AVLTrojan[Packed]/Win32.Krap
KingsoftWin32.HeurC.KVM011.a.(kcloud)
ArcabitTrojan.Lazy.D1B423
ViRobotTrojan.Win32.A.Zbot.280759
ZoneAlarmPacked.Win32.Krap.iu
MicrosoftVirTool:Win32/Obfuscator.ADH
AhnLab-V3Trojan/Win32.Zbot.R23747
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34212.sq1@aifPsndi
ALYacGen:Variant.Lazy.111651
MAXmalware (ai score=100)
VBA32BScope.TrojanPSW.Panda
TrendMicro-HouseCallMal_Ransom-1
RisingSpyware.Zbot!8.16B (CLOUD)
SentinelOneStatic AI – Malicious PE
FortinetW32/ZBOT.HL!tr
AVGWin32:Karagany
PandaBck/Qbot.AO
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Lazy.111651?

Lazy.111651 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment