Malware

What is “Lazy.13267”?

Malware Removal

The Lazy.13267 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.13267 virus can do?

  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Lazy.13267?


File Info:

name: A28E6A97B7C2045BDFDD.mlw
path: /opt/CAPEv2/storage/binaries/06bf85362cbf8c905ec94dcf26c69b526cde2b855a2ff3afb3a83db7c5452b36
crc32: EC0A696F
md5: a28e6a97b7c2045bdfddb13487667e94
sha1: 24458ea7750e1e1673c17624bac120e17d269184
sha256: 06bf85362cbf8c905ec94dcf26c69b526cde2b855a2ff3afb3a83db7c5452b36
sha512: 43d23997e2c79200fd417345520ca46ba02cf481d3826556e66e836f3d88243dc048e7dbbb9ca9bcb51aeb8639f2f1b138a6d35904ebd57f6cd7e5bea37ff693
ssdeep: 24576:/HX6lyKJ0hkRpyPHlJSywYIqRGK9+kbA:v6llJ0hk7UHlOYIqRGVk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1973528117AB9C457E0660030D96ACBF83922BCA1EE65495B3B913F2FFC357409921F6E
sha3_384: a5a6defba9c3b01ec4bd86c60b169bc3c86a4f054977bb3b1a6b86a0f4d96e3ddcf1a65998638f63a76d759a1e9c5ab0
ep_bytes: e8e7040000e97afeffff558bec56ff75
timestamp: 2021-01-22 08:48:08

Version Info:

Translation: 0x0409 0x04b0
CompanyName: Don HO don.h@free.fr
FileDescription: Notepad++ : a free (GNU) source code editor
FileVersion: 7.71
InternalName: npp.exe
LegalCopyright: Copyleft 1998-2016 by Don HO
OriginalFilename: Notepad++.exe
ProductName: Notepad++
ProductVersion: 7.71

Lazy.13267 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.13267
FireEyeGeneric.mg.a28e6a97b7c2045b
ALYacGen:Variant.Lazy.13267
MalwarebytesMachineLearning/Anomalous.100%
VIPREGen:Variant.Lazy.13267
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0056a5f91 )
AlibabaTrojanDownloader:Win32/Satacom.fd187522
K7GWTrojan-Downloader ( 0056a5f91 )
Cybereasonmalicious.7b7c20
CyrenW32/Satacom.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Satacom.L
CynetMalicious (score: 100)
APEXMalicious
KasperskyHEUR:Trojan.Win32.Agentb.gen
BitDefenderGen:Variant.Lazy.13267
TencentWin32.Trojan.Agentb.Qzfl
EmsisoftGen:Variant.Lazy.13267 (B)
F-SecureHeuristic.HEUR/AGEN.1306454
ZillyaTrojan.Agent.Win32.1694020
McAfee-GW-EditionGenericRXNK-OM!A28E6A97B7C2
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Lazy.13267
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1306454
MAXmalware (ai score=83)
Antiy-AVLTrojan[Downloader]/Win32.Satacom
XcitiumMalware@#3fk7ex7xg79ay
ArcabitTrojan.Lazy.D33D3
ZoneAlarmHEUR:Trojan.Win32.Agentb.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Malware/Gen.Reputation.C4306666
McAfeeGenericRXNK-OM!A28E6A97B7C2
VBA32BScope.Trojan.Khalesi
Cylanceunsafe
PandaTrj/GdSda.A
RisingDownloader.Satacom!8.113B5 (TFE:1:JhQflyNkoJF)
IkarusTrojan-Downloader.Win32.Satacom
FortinetW32/Satacom.L!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Lazy.13267?

Lazy.13267 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment