Malware

Should I remove “Lazy.112743”?

Malware Removal

The Lazy.112743 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.112743 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • .NET file is packed/obfuscated with SmartAssembly
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup

How to determine Lazy.112743?


File Info:

name: 683C9C00200F5D5EA639.mlw
path: /opt/CAPEv2/storage/binaries/365bf3f5b3ee29719eabb5089a829822a1fa4cbab8c5515b5d4b6971701f1c90
crc32: DA7200EA
md5: 683c9c00200f5d5ea639f2fd3229171f
sha1: 759de3a0527a2edf58d3abc04c9c32f379d86471
sha256: 365bf3f5b3ee29719eabb5089a829822a1fa4cbab8c5515b5d4b6971701f1c90
sha512: de60dcaaca6a8cfce44b4672866cef8dd4e853873315105fb1524d9c31a6fc8367ee1251438f04a1caeee46100db1c592c28aa710ef5800c02d264f10cb66cdc
ssdeep: 6144:iR6RW9tbY7XnCYF7QUNozR/KvKdPij6/KErB3brVIYRMr4okKNegz0sOxwFuCRDt:T0YF7mEvKF95/w4o1CwYCRDP55Luubv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CEF4392DBFAE5E11C6690777E7D291740282DC2A11C4E35F64F93EA40E353DA8886A1F
sha3_384: 678355a595906da7af4a6c71bda8d546a96d96ac838e1064e90f9f82c34eff6bae1eb3a235bb29fc5efb3c17a2e452b8
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-01-30 15:52:30

Version Info:

Translation: 0x040c 0x04e4
FileDescription: ToYcon
FileVersion: 0.8.0.0
InternalName: ToYcon
LegalCopyright: © Lefreut 2006-2009
OriginalFilename: a.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0
Author: Lefreut

Lazy.112743 also known as:

LionicTrojan.MSIL.Disfa.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.683c9c00200f5d5e
McAfeeArtemis!683C9C00200F
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3685746
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00563f1d1 )
AlibabaTrojan:MSIL/Disfa.df9fdcd7
K7GWTrojan ( 00563f1d1 )
Cybereasonmalicious.0200f5
BitDefenderThetaGen:NN.ZemsilF.34182.Um0@aKom4obe
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.VDW
TrendMicro-HouseCallTROJ_GEN.R002C0WAV22
Paloaltogeneric.ml
KasperskyHEUR:Trojan.MSIL.Disfa.gen
BitDefenderGen:Variant.Lazy.112743
MicroWorld-eScanGen:Variant.Lazy.112743
AvastWin32:CrypterX-gen [Trj]
TencentMsil.Trojan.Disfa.Wnwm
EmsisoftGen:Variant.Lazy.112743 (B)
TrendMicroTROJ_GEN.R002C0WAV22
McAfee-GW-EditionBehavesLike.Win32.Generic.bm
SophosMal/Generic-S
IkarusTrojan.MSIL.Crypt
AviraHEUR/AGEN.1114266
Antiy-AVLTrojan/Generic.ASMalwS.351C74B
MicrosoftBackdoor:MSIL/Bladabindi.AL
ZoneAlarmHEUR:Trojan.MSIL.Disfa.gen
GDataGen:Variant.Lazy.112743
SentinelOneStatic AI – Malicious PE
AhnLab-V3Malware/Win32.RL_Generic.C4069506
VBA32TScope.Trojan.MSIL
ALYacGen:Variant.Lazy.112743
APEXMalicious
RisingTrojan.Generic/MSIL@AI.98 (RDM.MSIL:cHOJZUw/KvJSJb58BRDWCg)
YandexTrojan.Kryptik!ZmXbYkb0WLo
MAXmalware (ai score=81)
FortinetMSIL/Kryptik.VDW!tr
AVGWin32:CrypterX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Lazy.112743?

Lazy.112743 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment