Malware

Should I remove “Lazy.113176 (B)”?

Malware Removal

The Lazy.113176 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.113176 (B) virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • CAPE detected the RedLine malware family
  • Binary compilation timestomping detected

How to determine Lazy.113176 (B)?


File Info:

name: C9A2524E4B86D36A8A85.mlw
path: /opt/CAPEv2/storage/binaries/3b91ccaeaae4e50c9d608546bb021b73c23a8a0b230bab1f493b70f57e77a64d
crc32: F4631CE4
md5: c9a2524e4b86d36a8a8543429aa7850e
sha1: c6de13e0fa74c6c56fe7eabc06ae99a60f337f30
sha256: 3b91ccaeaae4e50c9d608546bb021b73c23a8a0b230bab1f493b70f57e77a64d
sha512: 5ee3c2c3526c4f4c6177f8a9213a26d52ef29aef97b0a9a3bb0c2de5835f3ad7b2cf464fcfdf5544349b8df7467a56c04f1afdfe91108a539e34e4e2948e94be
ssdeep: 3072:+35n6/LtakhelhhdqRBKNMM6RR2Ugwetho7z6pg+2B:KM/htUlbgfKCYthKe
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15C045C5533DA8E14E7BE5A70D1F2145083B5EA47BB23D78E2CC424E50E52740FA26BEE
sha3_384: 7e8dee9bcd03b186d7ca7385fe088c412db9376aa7a1a50a624bc5928f74cb36a80be65ec846b43b689d51f93cbfc78a
ep_bytes: ff250020400000000000000000000000
timestamp: 2097-04-27 06:10:35

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: Gentleness.exe
LegalCopyright:
OriginalFilename: Gentleness.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Lazy.113176 (B) also known as:

BkavW32.AIDetectNet.01
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.113176
FireEyeGeneric.mg.c9a2524e4b86d36a
ALYacGen:Variant.Lazy.113176
CylanceUnsafe
BitDefenderGen:Variant.Lazy.113176
Cybereasonmalicious.0fa74c
CyrenW32/MSIL_Agent.BJO.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of MSIL/Spy.Agent.DFY
APEXMalicious
ClamAVWin.Trojan.Redline-9938775-1
KasperskyHEUR:Trojan-PSW.MSIL.Stealer.gen
RisingStealer.Agent!1.DC63 (CLASSIC)
Ad-AwareGen:Variant.Lazy.113176
EmsisoftGen:Variant.Lazy.113176 (B)
DrWebTrojan.PWS.Stealer.32664
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
SophosGeneric ML PUA (PUA)
IkarusTrojan-Spy.MSIL.Agent
GDataGen:Variant.Lazy.113176
JiangminTrojan.PSW.MSIL.doet
AviraHEUR/AGEN.1235899
MAXmalware (ai score=86)
ZoneAlarmHEUR:Trojan-PSW.MSIL.Reline.gen
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.C4036845
Acronissuspicious
McAfeeArtemis!C9A2524E4B86
VBA32Trojan-Stealer.MSIL.gen
MalwarebytesSpyware.DiscordStealer
PandaTrj/GdSda.A
TencentMsil.Trojan-qqpass.Qqrob.Taoo
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetMSIL/Agent.DFY!tr.spy
BitDefenderThetaGen:NN.ZemsilF.34638.lm1@aqUYqEi
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Lazy.113176 (B)?

Lazy.113176 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment