Malware

Lazy.213058 (B) removal tips

Malware Removal

The Lazy.213058 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.213058 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Collects information to fingerprint the system
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Lazy.213058 (B)?


File Info:

name: 7075D340AA96E68C7445.mlw
path: /opt/CAPEv2/storage/binaries/b0169ffe439939dcbf062edd50e157d9132a8f2f9b4873c466e4a1da91ee8148
crc32: BFCCADB7
md5: 7075d340aa96e68c744557b95e76e839
sha1: f933766144d82f7f865d86f6bb25815656a5c3a8
sha256: b0169ffe439939dcbf062edd50e157d9132a8f2f9b4873c466e4a1da91ee8148
sha512: d03513297bdd6aa50f88ea6c9ff922729bbf90d2fabec3b4deeada2c08928b15ea41f65fd6bdc310d5c720b54aed69f674a1c6e2e5ea847e03ad45da6765074d
ssdeep: 3072:wPU09UjrL5vSfmYYnS4e59YeIQ9lv6bQESE6asU9Jr/DlnH:YlUTxSfmxS4eo0zviQI6I9hrlH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T187349CF48180623AD8D842F55C82AD398E2DFC664A986DDB11897CD63FB35C487EE41F
sha3_384: 448f9c1fb16cff756a00a41f59a27c270bfb219c82fcb2aefd28a16d966fb705c60ddfec699fc1d7110f54d0a6fee95c
ep_bytes: 558bec51558f05f06d4300ff35f06d43
timestamp: 2013-03-21 16:46:21

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft DirectPlay Voice Test
FileVersion: 5.03.2600.5512 (xpsp.080413-0845)
InternalName: dpvsetup.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: dpvsetup.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 5.03.2600.5512
Translation: 0x0409 0x04b0

Lazy.213058 (B) also known as:

BkavW32.AIDetect.malware2
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Lazy.213058
ClamAVWin.Packed.Shipup-6804175-0
FireEyeGeneric.mg.7075d340aa96e68c
CAT-QuickHealTrojanDropper.Gepys.A
ALYacGen:Variant.Lazy.213058
MalwarebytesGeneric.Trojan.Malicious.DDS
ZillyaTrojan.ShipUp.Win32.1153
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0042f5451 )
K7GWTrojan ( 0042f5451 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Trojan.Agent.eq
VirITTrojan.Win32.Agent4.AKLH
CyrenW32/Zbot.JC.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.AXID
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.ShipUp.bok
BitDefenderGen:Variant.Lazy.213058
NANO-AntivirusTrojan.Win32.ShipUp.bobrvr
AvastWin32:Gepys-J [Trj]
TencentTrojan.Win32.Shipup.yw
TACHYONTrojan/W32.Shipup.243480.B
EmsisoftGen:Variant.Lazy.213058 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen7
DrWebTrojan.Redirect.140
VIPREGen:Variant.Lazy.213058
TrendMicroTROJ_KRYPTK.SML3
McAfee-GW-EditionPWS-Zbot-FATW!7075D340AA96
Trapminemalicious.high.ml.score
SophosTroj/Gyepis-B
SentinelOneStatic AI – Malicious PE
JiangminTrojan/ShipUp.jp
AviraTR/Crypt.XPACK.Gen7
Antiy-AVLTrojan/Win32.ShipUp
XcitiumTrojWare.Win32.Kryptik.AYQE@4wlbfl
ArcabitTrojan.Lazy.D34042
ZoneAlarmTrojan.Win32.ShipUp.bok
GDataWin32.Trojan.PSE.1KR2NFM
GoogleDetected
AhnLab-V3Trojan/Win32.Shipup.R58811
Acronissuspicious
McAfeePWS-Zbot-FATW!7075D340AA96
MAXmalware (ai score=88)
VBA32BScope.Malware-Cryptor.Hlux
Cylanceunsafe
PandaTrj/Hexas.HEU
TrendMicro-HouseCallTROJ_KRYPTK.SML3
RisingTrojan.Kryptik!1.AB8B (CLASSIC)
IkarusTrojan.Win32.ShipUp
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.AYTK!tr
BitDefenderThetaAI:Packer.72F4AF731F
AVGWin32:Gepys-J [Trj]
DeepInstinctMALICIOUS

How to remove Lazy.213058 (B)?

Lazy.213058 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment