Categories: Malware

Lazy.208662 removal

The Lazy.208662 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.208662 virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Authenticode signature is invalid
  • Writes to the spooler folder, potential vulnerability or printer driver install
  • Collects information to fingerprint the system
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Lazy.208662?


File Info:

name: 169E8099CC70DB1F26D9.mlwpath: /opt/CAPEv2/storage/binaries/2786c937dad2564db25c0d70d48fae04078d370536e437ca8b698a831dcaf8bccrc32: A83D0971md5: 169e8099cc70db1f26d92bae84b999efsha1: 0ab61dbc6958b8588ad78b2eef24aa3a86e22277sha256: 2786c937dad2564db25c0d70d48fae04078d370536e437ca8b698a831dcaf8bcsha512: 2aca68bf79781542f4d70944e10b838c05f181cbaea1eb3b0298482d39f5e6fce2b6331fc8555b7ed0c3bbdd3af314e8757f4cda7a9710531e71c09d4772965dssdeep: 1536:2u7wR5yuRvoMCnxkiBWF6DlB7JX/VU7RYwenJ9ziOmjcn+T7wOILqmi0/DjDTfek:24q5ykvHCnG2WF6pB4VLeDz5SEtumi2jtype: PE32 executable (GUI) Intel 80386, for MS Windowstlsh: T16793D08DBF416836E643A7F95E236691877F3C380C053E4AB2087A9F1F7A542DBA441Dsha3_384: 5a660a9cccaadc7b9afc3fab5dd0fb83068188234da19c865453e168020fe1af89ff7916877beb5465601f665347cd5bep_bytes: 558bec83c4f068d02d00008f056d8041timestamp: 2010-11-21 22:20:21

Version Info:

FileVersion: 1.3.0.0ProductVersion: 1.3CompanyName: LAVALYSFileDescription: Kernel Mode Driver ManagerInternalName: KmdManagerLegalCopyright: Copyright © 2006OriginalFilename: KmdManager.exeProductName: Kernel Mode Driver ManagerTranslation: 0x0409 0x04b0

Lazy.208662 also known as:

Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Lavandos.m!c
DrWeb Trojan.WinSpy.977
MicroWorld-eScan Gen:Variant.Lazy.208662
FireEye Generic.mg.169e8099cc70db1f
Skyhigh GenericRXVE-EG!169E8099CC70
ALYac Gen:Variant.Lazy.208662
VIPRE Gen:Variant.Lazy.208662
Sangfor Backdoor.Win32.Lavandos.e
K7AntiVirus Trojan ( 001ddbf41 )
BitDefender Gen:Variant.Lazy.208662
K7GW Trojan ( 001ddbf41 )
Cybereason malicious.c6958b
BitDefenderTheta Gen:NN.ZexaF.36792.fu1@aO1Dddmi
VirIT Trojan.Win32.WinSpy.BLP
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 Win32/Hodprot.AG
APEX Malicious
ClamAV Win.Trojan.Generic-6260334-0
Kaspersky Backdoor.Win32.Lavandos.e
Alibaba Malware:Win32/km_2c05f.None
NANO-Antivirus Trojan.Win32.Lavandos.cwjxo
Sophos Mal/Generic-S
Google Detected
F-Secure Trojan.TR/Crypt.ZPACK.Gen
Zillya Backdoor.Lavandos.Win32.208
Trapmine malicious.moderate.ml.score
Emsisoft Gen:Variant.Lazy.208662 (B)
Ikarus Trojan.Win32.Hodprot
Webroot W32.Malware.Gen
Varist W32/Risk.NRUJ-1445
Avira TR/Crypt.ZPACK.Gen
MAX malware (ai score=100)
Antiy-AVL Trojan[Backdoor]/Win32.Lavandos
Kingsoft malware.kb.a.1000
Microsoft Trojan:Win32/Parchood.A
Xcitium Backdoor@#2tfeubssabr6i
Arcabit Trojan.Lazy.D32F16
ZoneAlarm Backdoor.Win32.Lavandos.e
GData Gen:Variant.Lazy.208662
Cynet Malicious (score: 100)
AhnLab-V3 Dropper/Win32.Vidro.C151022
McAfee GenericRXVE-EG!169E8099CC70
DeepInstinct MALICIOUS
VBA32 Trojan.MTA.01161
Cylance unsafe
Panda Generic Malware
Rising Backdoor.Lavandos!8.2F9C (CLOUD)
Yandex Backdoor.Lavandos!EbjZmO4dYIM
SentinelOne Static AI – Suspicious PE
MaxSecure Trojan.Malware.2639556.susgen
Fortinet W32/Lavandos.E!tr.bdr
AVG Win32:FakeSysdef-U [Trj]
Avast Win32:FakeSysdef-U [Trj]
CrowdStrike win/malicious_confidence_90% (W)

How to remove Lazy.208662?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

MSIL/GenKryptik.GXIZ information

The MSIL/GenKryptik.GXIZ is considered dangerous by lots of security experts. When this infection is active,…

2 months ago

Malware.AI.2789448175 (file analysis)

The Malware.AI.2789448175 is considered dangerous by lots of security experts. When this infection is active,…

2 months ago

Jalapeno.1878 removal instruction

The Jalapeno.1878 is considered dangerous by lots of security experts. When this infection is active,…

2 months ago

What is “Trojan.Heur3.LPT.YmKfaKBcBekib”?

The Trojan.Heur3.LPT.YmKfaKBcBekib is considered dangerous by lots of security experts. When this infection is active,…

2 months ago

How to remove “Worm.Win32.Vobfus.exmt”?

The Worm.Win32.Vobfus.exmt is considered dangerous by lots of security experts. When this infection is active,…

2 months ago

About “TrojanDownloader:Win32/Beebone.JO” infection

The TrojanDownloader:Win32/Beebone.JO is considered dangerous by lots of security experts. When this infection is active,…

2 months ago