Malware

Lazy.135384 removal instruction

Malware Removal

The Lazy.135384 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.135384 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • .NET file is packed/obfuscated with Confuser
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Lazy.135384?


File Info:

name: 51144815898650811810.mlw
path: /opt/CAPEv2/storage/binaries/acb32a1bf446998109b614cc2169290db0d00037a6390171851fa97c72829d04
crc32: 39F2413F
md5: 5114481589865081181064e89c4bfc7b
sha1: 47eb4896d7bf1a25e956c80079ac37f181c2bbd4
sha256: acb32a1bf446998109b614cc2169290db0d00037a6390171851fa97c72829d04
sha512: 14ed2ce1e905d284daa4c9ba31c0b773673a9e9e737301543f2297eec42f4207e0d985e7f07f97207a7ef855fb71303671d830187666475eb83fc398b53e7540
ssdeep: 6144:wn84LSyGMujQDegui82HbObA6aXEvU+Aa9Mn9ddm9ygaptwD6IveTa6fz9chFaVb:wRqQDegui82HbObA6aXEvU+Aa9Mn9vmc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E76450FB315077EEDC27D43AE94B5C10D980B8A7438F628B9387927A564E646CF046E3
sha3_384: b3d170038b9972dc2936a1ec73a832b60dc2b51b53c24c0969c783b58f9d1677bd2ebd7ce365a8b5913b01aead3a48f0
ep_bytes: ff250020400000000000000000000000
timestamp: 2062-12-30 15:31:23

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: AmongUsHack
FileVersion: 1.0.0.0
InternalName: AmongUsHack.exe
LegalCopyright: Copyright © 2022
LegalTrademarks:
OriginalFilename: AmongUsHack.exe
ProductName: AmongUsHack
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Lazy.135384 also known as:

LionicTrojan.Win32.Bulz.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.135384
FireEyeGeneric.mg.5114481589865081
ALYacGen:Variant.Lazy.135384
CylanceUnsafe
SangforTrojan.Win32.Sabsik.FL
Cybereasonmalicious.589865
BitDefenderThetaGen:NN.ZemsilF.34232.sm0@a0AHPrb
CyrenW32/Trojan.KQSJ-4821
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002H09B822
Paloaltogeneric.ml
BitDefenderGen:Variant.Lazy.135384
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Lazy.135384
EmsisoftGen:Variant.Lazy.135384 (B)
McAfee-GW-EditionBehavesLike.Win32.Trojan.fh
SophosGeneric ML PUA (PUA)
GDataGen:Variant.Lazy.135384
Antiy-AVLTrojan/Generic.ASMalwS.3527A09
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Lazy.D210D8
MicrosoftProgram:Win32/Uwamson.A!ml
CynetMalicious (score: 100)
McAfeeArtemis!511448158986
MAXmalware (ai score=87)
APEXMalicious
RisingMalware.Obfus/MSIL@AI.100 (RDM.MSIL:vwj+wXHovuXE36DiyARukw)
SentinelOneStatic AI – Malicious PE
FortinetMalicious_Behavior.SB
AVGWin32:Malware-gen
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.300983.susgen

How to remove Lazy.135384?

Lazy.135384 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment