Malware

How to remove “Lazy.118611”?

Malware Removal

The Lazy.118611 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.118611 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Uses Windows utilities for basic functionality
  • Deletes executed files from disk
  • Uses csc.exe C# compiler to build and execute code
  • Uses suspicious command line tools or Windows utilities

How to determine Lazy.118611?


File Info:

name: 38B7048268CF859FF4CA.mlw
path: /opt/CAPEv2/storage/binaries/c77e28538ae7ff47dd27d94f8e90300d3ac895d8c779d8c786f526bee7db262a
crc32: EFF2C9F7
md5: 38b7048268cf859ff4ca35e76d1a0683
sha1: d23ab1045ee82875c63a4377af17c9c708037ca6
sha256: c77e28538ae7ff47dd27d94f8e90300d3ac895d8c779d8c786f526bee7db262a
sha512: a8d1d50e3d5f7ed54ce85ea44394c4c5a78d539e002992ab3411a91e5ae395ef0bd9889e8c02c13cab12b1c8375dd6a9f5c9390a80c01e29a0f7c03e2b0eb96a
ssdeep: 49152:KDQESlaihCELLZCHo477kShlgf9aP3a9VjEc:
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DDC522B0E8673E96F7940B758D032B59EE664A40087CB01F50BA7E1009FF794AAF4D79
sha3_384: 8fcfff2603f9ebf0e151490c4c5eebfd9a53416b4bc59dbffe64fd43c265a17153081e774c51faa8de55439f0d80ea90
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-09-02 21:22:27

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: Dogs Free Database.exe
LegalCopyright:
OriginalFilename: Dogs Free Database.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Lazy.118611 also known as:

BkavW32.AIDetectNet.01
MicroWorld-eScanGen:Variant.Lazy.118611
FireEyeGeneric.mg.38b7048268cf859f
CylanceUnsafe
VIPREGen:Variant.Lazy.118611
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
K7GWTrojan ( 700000121 )
Cybereasonmalicious.268cf8
BitDefenderThetaGen:NN.ZemsilF.34606.Hs0@ayi@NXc
CyrenW32/MSIL_Injector.XJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Injector.HN
APEXMalicious
ClamAVWin.Packed.Gamarue-6817673-0
KasperskyHEUR:Trojan.MSIL.Generic
BitDefenderGen:Variant.Lazy.118611
CynetMalicious (score: 100)
AvastMSIL:GenMalicious-AQH [Trj]
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:Cs0OhO5MygvgOV/KFGOCmQ)
Ad-AwareGen:Variant.Lazy.118611
EmsisoftGen:Variant.Lazy.118611 (B)
Trapminesuspicious.low.ml.score
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.ndon
AviraTR/Dropper.Gen
MAXmalware (ai score=89)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Lazy.118611
GoogleDetected
Acronissuspicious
ALYacGen:Variant.Lazy.118611
MalwarebytesMalware.AI.3417075117
IkarusTrojan-Dropper.Small
FortinetMSIL/Injector.HN!tr
AVGMSIL:GenMalicious-AQH [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Lazy.118611?

Lazy.118611 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment