Malware

Lazy.174563 information

Malware Removal

The Lazy.174563 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.174563 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Sets an Autoconfig URL, likely to hijack browser settings.

How to determine Lazy.174563?


File Info:

name: 0E773DD034727B654818.mlw
path: /opt/CAPEv2/storage/binaries/3642912241e41a0799b1c32217315455681e847c47381f8b00b720722d92a3cb
crc32: FFB57B46
md5: 0e773dd034727b654818cd57b0562862
sha1: 1b7bbd3937521a18e2c13b17475d3b45d09262a7
sha256: 3642912241e41a0799b1c32217315455681e847c47381f8b00b720722d92a3cb
sha512: 7c6d260fded58c8fea62a84d6790708ec4f84d8a2a100084a51c240ac23189420498d016250ba8e86771c8895f62fa3b808f569268b1b27fb5483703e24e0460
ssdeep: 768:i8cx+fb0czGSIXBzJ70F9vKpYZDNl/ynbcuyD7Uzf:s+fAczjIXBFAEpYl/ynouy8z
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DFE2D00BECEE59CCD2D122B34475788D0AD01149578087E5D6781227FEC56642EBFEEB
sha3_384: 627f4896781850d20cfc8a2f143464cc2dafddd0a2d333ce589a2d1a61bd467db4c79daf36bb6f879d6b8d2a6b6225a3
ep_bytes: 60be003041008dbe00e0feff5789e58d
timestamp: 2022-04-18 05:00:37

Version Info:

0: [No Data]

Lazy.174563 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Lazy.174563
ALYacGen:Variant.Lazy.174563
CylanceUnsafe
Cybereasonmalicious.937521
ESET-NOD32a variant of Win32/TrojanProxy.Agent.OEO
KasperskyTrojan.Win32.ProxyChanger.aoe
BitDefenderGen:Variant.Lazy.174563
AvastWin32:TrojanX-gen [Trj]
TencentWin32.Trojan.Lazy.Hzb
Ad-AwareGen:Variant.Lazy.174563
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Generic.nc
SentinelOneStatic AI – Malicious PE
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.0e773dd034727b65
EmsisoftGen:Variant.Lazy.174563 (B)
IkarusTrojan-Proxy.Agent
GDataGen:Variant.Lazy.174563
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Lazy.D2A9E3
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
AhnLab-V3Malware/Win.Generic.C5018350
McAfeeArtemis!0E773DD03472
MalwarebytesMalware.Heuristic.1003
APEXMalicious
RisingTrojan.Agent!8.B1E (TFE:dGZlOgXqmZL5JygxAw)
MAXmalware (ai score=80)
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Lazy.174563?

Lazy.174563 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment