Malware

Lazy.177566 removal instruction

Malware Removal

The Lazy.177566 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.177566 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the EnigmaStub malware family
  • Anomalous binary characteristics

How to determine Lazy.177566?


File Info:

name: 2E86E8694C27D4118D8B.mlw
path: /opt/CAPEv2/storage/binaries/91af00f3754eb3fc212402cebe5e064f636201dc93eecf8c7140eec57329a335
crc32: C35C7A15
md5: 2e86e8694c27d4118d8b8bcb3cd31a29
sha1: e5cc22e0728f7bc5d6afaece4b849049a62ed575
sha256: 91af00f3754eb3fc212402cebe5e064f636201dc93eecf8c7140eec57329a335
sha512: bc8e6ccf49afe2451aef5257de33586390f79ebed595ba9b4d1d56f2c4621f9ffd4b321eea048cc0f2a45a1b0425c6fba27d79a8dfff07e3ba33bef1ad33719e
ssdeep: 24576:U83ZjiBpGbylRcm8Na5erCU2lyb7jGFbuif0yvyGQgsdJ/bS6hixh7siBggglgBa:UiZjS9lRBca5brlE7WRyxgs/mUA7JBgB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15D653359C77A63D1F74623FE3E0358DE9C20DCF840D42D6096D8AC8979D4B982ABE076
sha3_384: 1fb2c53d1454b196c7211676a0456e61aa4e0359a9b1578ae0e1973162a39eef7fb7a7b5971d3dd84fd60f19a0d85f54
ep_bytes: eb08004603000000000060e800000000
timestamp: 2010-12-09 18:58:13

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName: Oracle Corporation
FileDescription: Java Update Scheduler
FileVersion: 2.8.301.9
InternalName: jusched.exe
LegalCopyright: Copyright©2022
LegalTrademarks:
OriginalFilename: jusched.exe
ProductName: Java Platform SE Auto Updater
ProductVersion: 2.8.301.9
Assembly Version: 2.8.301.9

Lazy.177566 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.177566
FireEyeGeneric.mg.2e86e8694c27d411
ALYacGen:Variant.Lazy.177566
CylanceUnsafe
Cybereasonmalicious.0728f7
CyrenW32/Trojan.FFG.gen!Eldorado
ESET-NOD32a variant of Win32/Packed.EnigmaProtector.M suspicious
APEXMalicious
ClamAVWin.Trojan.Generic-6898101-0
BitDefenderGen:Variant.Lazy.177566
Ad-AwareGen:Variant.Lazy.177566
EmsisoftGen:Variant.Lazy.177566 (B)
F-SecureHeuristic.HEUR/AGEN.1231071
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminemalicious.high.ml.score
SophosML/PE-A
IkarusTrojan.Win32.Enigma
GDataGen:Variant.Lazy.177566
AviraHEUR/AGEN.1231071
ArcabitTrojan.Lazy.D2B59E
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C2724930
Acronissuspicious
McAfeeGenericRXMR-KT!D87D07159FF6
MAXmalware (ai score=85)
VBA32TrojanDropper.Convagent
MalwarebytesMalware.Heuristic.1003
ZonerProbably Heur.ExeHeaderL
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
BitDefenderThetaGen:NN.ZexaF.34742.Ez3@aywVJrb
AVGWin32:Evo-gen [Susp]
AvastWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Lazy.177566?

Lazy.177566 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment