Malware

Lazy.163761 (file analysis)

Malware Removal

The Lazy.163761 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.163761 virus can do?

  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Lazy.163761?


File Info:

name: 55736EF39FF5FB3E0BC4.mlw
path: /opt/CAPEv2/storage/binaries/847935d8ad5c5a02161932da390b1a1987f4060b3962a4a457d456d845437ae6
crc32: 26D4491B
md5: 55736ef39ff5fb3e0bc45ed68395efbd
sha1: 16a1a2990bda1c747260d4898ebe30027251965e
sha256: 847935d8ad5c5a02161932da390b1a1987f4060b3962a4a457d456d845437ae6
sha512: 441c8b035b7fce7564993088737aed8e543ce2db67d20296d23d02889b39bce3db9730912cb8fb8c004def069071adfce36514dafba37b668531d1b621473452
ssdeep: 393216:6bFb3bPk5HPhJCFMg25x8qgSmIbr/Asb8nmFi:yJWhUdIb8sYmE
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T13DD6AE01F5C284B1DFE38178A2A2F35F9725FC8281249DAAF95C36859F336915D2F21E
sha3_384: e199308e0f4bd30b102b401472d15bcd7a96c0065ad1876d6bc6f4cdef36087600d2321470a86997f95b40cdf47d7a04
ep_bytes: ff250020400000000000000000000000
timestamp: 2007-10-24 03:31:10

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft .NET Assembly Registration Utility
FileVersion: 2.0.50727.1433 (REDBITS.050727-1400)
InternalName: RegAsm.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: RegAsm.exe
ProductName: Microsoft® .NET Framework
ProductVersion: 2.0.50727.1433
Comments: Flavor=Retail
Translation: 0x0409 0x04b0

Lazy.163761 also known as:

tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Lazy.163761
ClamAVWin.Malware.Generic-9839999-0
FireEyeGen:Variant.Lazy.163761
CAT-QuickHealTrojan.AgenFC.S20327787
ALYacGen:Variant.Lazy.163761
CylanceUnsafe
ZillyaDropper.Agent.Win32.510507
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/grayware_confidence_60% (W)
CyrenW32/MSIL_Kryptik.CZ.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.FIF
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Lazy.163761
NANO-AntivirusTrojan.Win32.Memery.bybqne
AvastWin32:DropperX-gen [Drp]
Ad-AwareGen:Variant.Lazy.163761
DrWebWin32.Siggen.16
VIPREGen:Variant.Lazy.163761
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
EmsisoftGen:Variant.Lazy.163761 (B)
SentinelOneStatic AI – Malicious PE
GDataMSIL.Trojan.PSE.1AJ2WXA
AviraHEUR/AGEN.1247639
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
GoogleDetected
Acronissuspicious
McAfeeArtemis!55736EF39FF5
MAXmalware (ai score=89)
VBA32Virus.Loch.271107
MalwarebytesLamer.Virus.FileInfector.DDS
YandexTrojan.Agent!AXRJ9YG7c6c
IkarusTrojan-Dropper.MSIL.Agent
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/SPNR.15EG12!tr
BitDefenderThetaAI:FileInfector.37DCC0A10D
AVGWin32:DropperX-gen [Drp]
Cybereasonmalicious.39ff5f

How to remove Lazy.163761?

Lazy.163761 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment