Malware

Should I remove “Lazy.209128”?

Malware Removal

The Lazy.209128 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.209128 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Lazy.209128?


File Info:

name: 11114EAD45F64884FDF6.mlw
path: /opt/CAPEv2/storage/binaries/4b455638d643b84772d18ce7e8a702df1f626ae680c147e40c603f1acf1a2010
crc32: F50561EA
md5: 11114ead45f64884fdf62e2039242ad1
sha1: 8c9a72a51b329bba8368ca16dc720f97c3b0685e
sha256: 4b455638d643b84772d18ce7e8a702df1f626ae680c147e40c603f1acf1a2010
sha512: f609b1bbd741a721874a25dca0b6f990d0553ec2067ae2e316550e0dca2d84f36d72b47b63ffa19fd112d1bb81339a4b5820e0f19ae0f6a833c376b9385c700f
ssdeep: 1536:Crvhus4zYuWEm9DY8L2vVeUSPlea92VAOPXibMF:CIxkuDmlL2vNuea94AnMF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E963DF8DE7FA6525D4F2423F08F3AA924B34D7544B6D58930E13290EE41F84057A5FFA
sha3_384: c0571838502ee129cd7b9bcd775724171e8d4ec1e719bb40009ab70b9722157966704b7dc6cb14b5ab310f19cff441a8
ep_bytes: e8ef1a00008b3df0a8410066b940000b
timestamp: 2009-03-30 01:21:19

Version Info:

Comments:
CompanyName: ComponentOne LLC
FileDescription: YrDrWeb For Windows d 2011
FileVersion: 5.0.572.1152
InternalName: Dr.Web for Windows U
LegalCopyright: Copyright (C) i DoctorWeb, Ltd., 1992-2011
LegalTrademarks:
OriginalFilename: 0qpratectk7G
ProductName: Dr.Web for Windows J8
ProductVersion: 5.0.572.1152
Translation: 0x0419 0x04e3

Lazy.209128 also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Lazy.209128
FireEyeGeneric.mg.11114ead45f64884
CAT-QuickHealTrojan.Renos.LX
SkyhighBehavesLike.Win32.Swrort.kc
ALYacGen:Variant.Lazy.209128
MalwarebytesTrojan.Agent
VIPREGen:Variant.Lazy.209128
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.Lazy.209128
K7GWTrojan ( 002056d81 )
K7AntiVirusTrojan ( 002056d81 )
BitDefenderThetaGen:NN.ZexaF.36792.eq0@aK5HkJmi
VirITTrojan.Win32.Cryptor.AH
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.LMQ
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:Hoax.Win32.FlashApp.a
AlibabaTrojan:Win32/FlashApp.b316a337
NANO-AntivirusTrojan.Win32.Kryptik.bwxyc
ViRobotTrojan.Win32.Jorik.67584
RisingTrojan.Skor!1.68E4 (CLASSIC)
TACHYONTrojan/W32.Jorik.67584
SophosMal/FakeAV-IZ
F-SecureTrojan-Downloader:W32/Renos.GTW
DrWebTrojan.DownLoader22.14950
ZillyaTrojan.Jorik.Win32.3563
TrendMicroTROJ_FAKEAV.SM1C
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Lazy.209128 (B)
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Lazy.209128
JiangminTrojan/Jorik.dns
WebrootW32.Rogue.Gen
GoogleDetected
AviraTR/Crypt.XPACK.Gen3
Antiy-AVLTrojan/Win32.Skor
KingsoftWin32.NotVirus.FlashApp.a
XcitiumTrojWare.Win32.Kryptik.VL@2qgufe
ArcabitTrojan.Lazy.D330E8
ZoneAlarmUDS:Hoax.Win32.FlashApp.a
MicrosoftTrojanDownloader:Win32/Renos.PT
VaristW32/FakeAlert.KN.gen!Eldorado
AhnLab-V3Trojan/Win32.FakeAV.R3323
McAfeeDownloader-CEW.ac
MAXmalware (ai score=100)
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_FAKEAV.SM1C
TencentTrojan.Win32.Jorik.Skor.nf
YandexTrojan.Codecpack.Gen.14
IkarusTrojan.Win32.Jorik
FortinetW32/Krypt.QKV!tr
AVGWin32:Crypt-ISH [Trj]
Cybereasonmalicious.51b329
AvastWin32:Crypt-ISH [Trj]

How to remove Lazy.209128?

Lazy.209128 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment