Malware

What is “Lazy.193439”?

Malware Removal

The Lazy.193439 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.193439 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • CAPE detected the Remcos malware family

How to determine Lazy.193439?


File Info:

name: AD178FB70B7DBE575354.mlw
path: /opt/CAPEv2/storage/binaries/0caa8fce868fb6f6a69d514151d7c520509cfc8ab2988161786377f01c46fd93
crc32: 3C9177E1
md5: ad178fb70b7dbe5753543ec560ca3eef
sha1: 775974c73a0c136a3338cfde2b5b217fe92cb293
sha256: 0caa8fce868fb6f6a69d514151d7c520509cfc8ab2988161786377f01c46fd93
sha512: c3fe96f8e8d1ce9444c40c99eeccd6d8121b3ae6e05e1a87c8a1a9ccf56b0aa66100b7a6c5cae910bb1756cef97ef01fba05944bb0bbc81e9d302e48085d2bb9
ssdeep: 3072:ZSoMeHUod+najOZpu9fgiipu6G/uPA54ygl66YE19TKdRg0zAZSuD8GcdB3KvvSu:ZL0/nd4KPy4jJzrT3EuRGFCS1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11A2412467979DA5EF19840F49810C2B837E54C261DEB798F96F5BE133D72980EECB022
sha3_384: cf1c849423a778916eb5dd2352d56fc51a925d78fcf6584df87f6d16d16091fd089b90176451312055c989d0903ccadf
ep_bytes: 60be007044008dbe00a0fbffc787002d
timestamp: 2022-08-20 16:46:22

Version Info:

0: [No Data]

Lazy.193439 also known as:

CynetMalicious (score: 100)
FireEyeGeneric.mg.ad178fb70b7dbe57
McAfeeGenericRXSQ-HG!91EC2C97C62B
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0057919d1 )
K7GWTrojan ( 0057919d1 )
Cybereasonmalicious.70b7db
CyrenW32/Remcos.P.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Rescoms.N
APEXMalicious
ClamAVWin.Trojan.Remcos-9841897-0
KasperskyVHO:Backdoor.Win32.Remcos.gen
BitDefenderGen:Variant.Lazy.193439
MicroWorld-eScanGen:Variant.Lazy.193439
AvastWin32:RATX-gen [Trj]
Ad-AwareGen:Variant.Lazy.193439
TACHYONBackdoor/W32.Remcos.433152
EmsisoftGen:Variant.Lazy.193439 (B)
VIPREGen:Variant.Lazy.193439
McAfee-GW-EditionBehavesLike.Win32.Dropper.dc
Trapminemalicious.high.ml.score
SophosML/PE-A
IkarusBackdoor.Remcos
GDataGen:Variant.Lazy.193439
JiangminBackdoor.Remcos.dpz
AviraBDS/Backdoor.Gen
Antiy-AVLTrojan/Generic.ASMalwS.522E
ArcabitTrojan.Lazy.D2F39F
MicrosoftTrojan:Win32/Sabsik.EN.B!ml
GoogleDetected
AhnLab-V3Backdoor/Win.BT.C5133422
ALYacGen:Variant.Lazy.193439
MAXmalware (ai score=83)
VBA32BScope.Trojan.Wacatac
MalwarebytesBackdoor.Remcos
RisingBackdoor.Convagent!8.123DC (TFE:5:SQFiVQegMgU)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Remcos.M!tr
BitDefenderThetaGen:NN.ZexaF.34606.nmGfaSVFmmbi
AVGWin32:RATX-gen [Trj]
PandaTrj/GdSda.A

How to remove Lazy.193439?

Lazy.193439 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment