Malware

About “Lazy.196746” infection

Malware Removal

The Lazy.196746 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.196746 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Dynamic (imported) function loading detected
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Lazy.196746?


File Info:

name: EA9696FCF486A86F2E48.mlw
path: /opt/CAPEv2/storage/binaries/fe5baace44a634cd58d107e4c33735b677951b60f5c118759f2ea02e41f72127
crc32: 08638BE4
md5: ea9696fcf486a86f2e4829203d443027
sha1: 3ed813196b65e8bb1638b8cf01f1f591d7bef804
sha256: fe5baace44a634cd58d107e4c33735b677951b60f5c118759f2ea02e41f72127
sha512: 6b3d4f4cb1463c3a35875ff2cc9d3328820ba88d003154fe6d0aec31061b03b04e301139713160c450a63ee20c33a53b5fe77a57af851b233d16957ef06cb198
ssdeep: 6144:jOsDlGBZ8rNWbikPJFKPF0ywgRs2X5nWO1ltqmFtxPDZZforvpA9rwo42:pw+NWbNPfpywgRsE5nWm2GfgDpkEod
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A555D0662B58E2ABC2774975CC5626BFC45A6C358EC5084EC311332D68F2BA3FB60497
sha3_384: 6c2456766372b1efd70c04d3ced34402cc191bec3312ab6deb8dffcc9fd6ea7acf5020d5f7e3be3223ebe9e65a43eded
ep_bytes: 6818e94e00e8f0ffffff000040000000
timestamp: 2022-06-09 16:35:56

Version Info:

Translation: 0x0409 0x04b0
CompanyName: KAWAY
ProductName: £ä_¾™×ä
FileVersion: 1.00
ProductVersion: 1.00
InternalName: £ä_¾™×ä
OriginalFilename: £ä_¾™×ä.exe

Lazy.196746 also known as:

BkavW32.AIDetect.malware2
ClamAVWin.Trojan.Ratx-9952190-0
FireEyeGeneric.mg.ea9696fcf486a86f
McAfeeGenericRXTI-PO!EA9696FCF486
CylanceUnsafe
Sangfor[MICROSOFT VISUAL BASIC V6.0]
K7AntiVirusTrojan ( 004c78141 )
K7GWTrojan ( 004c78141 )
Cybereasonmalicious.96b65e
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.CECD
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Trojan-Ransom.Win32.Convagent.gen
BitDefenderGen:Variant.Lazy.196746
MicroWorld-eScanGen:Variant.Lazy.196746
AvastWin32:RATX-gen [Trj]
RisingTrojan.Injector!8.C4 (TFE:dGZlOgW84y+Ro2HsEw)
Ad-AwareGen:Variant.Lazy.196746
EmsisoftGen:Variant.Lazy.196746 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebBackDoor.Bladabindi.13678
ZillyaTrojan.Injector.Win32.1539808
McAfee-GW-EditionGenericRXTI-PO!EA9696FCF486
Trapminemalicious.moderate.ml.score
SophosML/PE-A
GDataGen:Variant.Lazy.196746
JiangminTrojan.Convagent.agh
AviraTR/Crypt.XPACK.Gen
ArcabitTrojan.Lazy.D3008A
ZoneAlarmVHO:Trojan-Ransom.Win32.Convagent.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Trojan/Win.Generic.R498808
ALYacGen:Variant.Lazy.196746
MAXmalware (ai score=87)
MalwarebytesMalware.AI.3910226547
TencentMalware.Win32.Gencirc.11fa2671
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.DZLM!tr
BitDefenderThetaGen:NN.ZevbaF.34742.vn0@aSIT0mdi
AVGWin32:RATX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Lazy.196746?

Lazy.196746 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment