Malware

What is “Lazy.138808”?

Malware Removal

The Lazy.138808 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.138808 virus can do?

  • Unconventionial language used in binary resources: Thai
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Lazy.138808?


File Info:

name: F7C8E24271538F28E76C.mlw
path: /opt/CAPEv2/storage/binaries/ed19a88fe06c9f26879a8f9e489fa86520b2f5aca7a4ea2d9bd41c155a187fc1
crc32: 66C60F15
md5: f7c8e24271538f28e76c3fb98480005e
sha1: 9a2c936c3178cf5ef81257035d6e0bb17a11e260
sha256: ed19a88fe06c9f26879a8f9e489fa86520b2f5aca7a4ea2d9bd41c155a187fc1
sha512: 218df875943d30182b8f9dd7cc214071dcd516cd16fc885f6c1539968da199d354713a695593c88871947bc538c1d6624e17b1dd6d9ad9dbe95e6d9fe9e5fab3
ssdeep: 98304:RpteKNPaI6R5plK36ZiFTHCOZx4Pg5gzAbgL4ovEL2tqUdSUopv97tdNTTZz:xeKNPil6FDFZ2Pg544bytTEF7dZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1307633907EE0AC85D5238DBC54E2CBA61CB49E98AF7A840D61D33BFD8F359054C58F4A
sha3_384: ddb5f0008844cbd3dc958c16785e6d472e4c5742a7333a07d87dd6dbb79804f826ebf999aa5cd998badc1001f4380c6e
ep_bytes: eb0800b84a000000000060e800000000
timestamp: 2022-02-08 03:41:35

Version Info:

FileDescription: RebirthRC MMO Launcher
FileVersion: 2.0.0.0
InternalName: RSUpdate.exe
OriginalFilename: RSUpdate.exe
ProductName: RebirthRC MMO Launcher
ProductVersion: 2.0.0.0
Translation: 0x0409 0x04e4

Lazy.138808 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Lazy.4!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Lazy.138808
FireEyeGeneric.mg.f7c8e24271538f28
CAT-QuickHealTrojan.GenericRI.S27545952
McAfeeArtemis!F7C8E2427153
SangforTrojan.Win32.Lazy.Vsnc
Cybereasonmalicious.271538
tehtrisGeneric.Malware
ZonerProbably Heur.ExeHeaderL
APEXMalicious
BitDefenderGen:Variant.Lazy.138808
EmsisoftGen:Variant.Lazy.138808 (B)
VIPREGen:Variant.Lazy.138808
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Lazy.138808
Antiy-AVLTrojan/Win32.PossibleThreat
ArcabitTrojan.Lazy.D21E38
GoogleDetected
BitDefenderThetaGen:NN.ZexaF.36250.@V0@aOajQilO
ALYacGen:Variant.Lazy.138808
MAXmalware (ai score=84)
VBA32TrojanDownloader.Adload
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H09DB23
IkarusTrojan.Swisyn
MaxSecureTrojan.Malware.205940342.susgen
FortinetW32/PossibleThreat
DeepInstinctMALICIOUS

How to remove Lazy.138808?

Lazy.138808 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment