Malware

Lazy.171009 removal

Malware Removal

The Lazy.171009 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.171009 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Lazy.171009?


File Info:

name: 326A1A4AD2B5CD0DBE37.mlw
path: /opt/CAPEv2/storage/binaries/0a92b4a1772442224999a5dbf87f7997ed7d5ead059f1ebbc7073f59268a9682
crc32: B24D5704
md5: 326a1a4ad2b5cd0dbe37fcb57cf94db7
sha1: 200edd224621b8b6fa156e417d70364d4ada2944
sha256: 0a92b4a1772442224999a5dbf87f7997ed7d5ead059f1ebbc7073f59268a9682
sha512: b474a0ae930984be75b9c2e5fbc3d930b9e86c55d7a64ee93fb5503e7b05897a354e535185effdda51e8dcd0384aa9d13702f4affb7865608132667c3c584d78
ssdeep: 6144:sISMPL+59NyQhDRZaaJsp7SEw6O4CiYyXLHwTlEIUZ09NLuu/fXos69i:sI0zeaikn6Obi9XLHwTlEkLLrfX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T128842372BE8C55AEC3C74AFE1D05709F028135E646BA46D61D20C9B4BB1FAE0971A21F
sha3_384: a6fbd8af636434defde75c10a085416e2e835f288b0c1a22638a358392ef01376529f72f94df2cfb0c698d8aa035919b
ep_bytes: 558bec83ec0c5357568bf3e948010000
timestamp: 2007-07-21 21:58:48

Version Info:

0: [No Data]

Lazy.171009 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Zbot.l!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Lazy.171009
FireEyeGeneric.mg.326a1a4ad2b5cd0d
ALYacGen:Variant.Lazy.171009
MalwarebytesMalware.Heuristic.1004
ZillyaTrojan.Zbot.Win32.1510
SangforSuspicious.Win32.Save.a
K7AntiVirusSpyware ( 000ab5191 )
BitDefenderGen:Variant.Lazy.171009
K7GWSpyware ( 000ab5191 )
Cybereasonmalicious.ad2b5c
CyrenW32/Trojan.CXOO-7417
SymantecPacked.Mystic!gen1
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.JBG
CynetMalicious (score: 100)
APEXMalicious
Paloaltogeneric.ml
KasperskyPacked.Win32.Krap.t
AlibabaTrojanPSW:Win32/Bulta.20626ff9
NANO-AntivirusTrojan.Win32.Krap.dfapls
AvastWin32:Fraudo [Trj]
RisingMalware.Undefined!8.C (TFE:3:vsMk4EsDDZG)
Ad-AwareGen:Variant.Lazy.171009
TACHYONTrojan-Spy/W32.ZBot.402432.K
EmsisoftGen:Variant.Lazy.171009 (B)
ComodoTrojWare.Win32.Spy.Zbot.ABH@1pwavx
DrWebTrojan.PWS.Panda.4
VIPREGen:Variant.Lazy.171009
TrendMicroTROJ_FAKEALE.SME
McAfee-GW-EditionBehavesLike.Win32.Dropper.fc
Trapminemalicious.high.ml.score
SophosMal/Generic-R + Mal/EncPk-IV
JiangminTrojanSpy.Zbot.knj
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.4
MicrosoftTrojan:Win32/Zbot.GTT!MTB
GDataGen:Variant.Lazy.171009
GoogleDetected
Acronissuspicious
McAfeeGeneric.dx!hv.cf
MAXmalware (ai score=100)
VBA32BScope.Trojan.Downloader
CylanceUnsafe
TrendMicro-HouseCallTROJ_FAKEALE.SME
YandexTrojanSpy.Zbot!z7oOQNvNGMM
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.1130901.susgen
FortinetW32/PackTDss.W!tr
BitDefenderThetaAI:Packer.142A5DB11E
AVGWin32:Fraudo [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Lazy.171009?

Lazy.171009 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment