Malware

Lazy.213058 removal tips

Malware Removal

The Lazy.213058 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.213058 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Transacted Hollowing
  • Collects information to fingerprint the system

How to determine Lazy.213058?


File Info:

name: 0D2171E5C52BBFB34C1C.mlw
path: /opt/CAPEv2/storage/binaries/20d53dedb08d524edaf6ed8d7e7965a9351ab1cca7aba0ea6c0f58bd19f74489
crc32: F5A9188D
md5: 0d2171e5c52bbfb34c1cd7659b42167a
sha1: 4005f1b83590e5b85427649710ee7cb8149483d8
sha256: 20d53dedb08d524edaf6ed8d7e7965a9351ab1cca7aba0ea6c0f58bd19f74489
sha512: 3f536a8541713ae25b3da8da959038e01aba4ba92c3da30cfb7db87446b3d5472d9694ce4754bf892f18085907fb5f491a35380554deb70a16bcdcbbcec6b098
ssdeep: 3072:BPUd9UjrL5vSfmGyKCjr2aoW/cqYW813Jg8mXQpESE6asU9Jr/DlnP:FmUTxSfmGQwGcqYW8JgIpI6I9hrlP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T157349DF59180623AD8D842F55C82AC3A8E2DFC214AA4ADDB11497DD63FB35C487EE41F
sha3_384: df4486a9aa0145c65c7bddd648697d1651ed5a768f9b950f987a8a74ac8fb50d2d5e4a8f151278c66cfd2bae66fc7991
ep_bytes: 558bec51558f05f06d4300ff35f06d43
timestamp: 2013-03-21 16:45:18

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft DirectPlay Voice Test
FileVersion: 5.03.2600.5512 (xpsp.080413-0845)
InternalName: dpvsetup.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: dpvsetup.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 5.03.2600.5512
Translation: 0x0409 0x04b0

Lazy.213058 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.ShipUp.lISW
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Lazy.213058
ClamAVWin.Packed.Shipup-6804175-0
FireEyeGeneric.mg.0d2171e5c52bbfb3
CAT-QuickHealTrojanDropper.Gepys.A
ALYacGen:Variant.Lazy.213058
CylanceUnsafe
ZillyaTrojan.ShipUp.Win32.1153
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0042f5451 )
AlibabaTrojan:Win32/ShipUp.c891af35
K7GWTrojan ( 0042f5451 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.257937FF1F
VirITTrojan.Win32.Agent4.AKLH
CyrenW32/Zbot.JC.gen!Eldorado
SymantecPacked.Generic.406
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.AXID
BaiduWin32.Trojan.Agent.eq
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.ShipUp.bok
BitDefenderGen:Variant.Lazy.213058
NANO-AntivirusTrojan.Win32.ShipUp.bobrvr
AvastWin32:Gepys-J [Trj]
TencentMalware.Win32.Gencirc.10b43fa9
Ad-AwareGen:Variant.Lazy.213058
TACHYONTrojan/W32.Shipup.243408
EmsisoftGen:Variant.Lazy.213058 (B)
ComodoTrojWare.Win32.Kryptik.AYQE@4wlbfl
DrWebTrojan.Redirect.140
VIPREGen:Variant.Lazy.213058
TrendMicroTROJ_KRYPTK.SML3
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
Trapminemalicious.high.ml.score
SophosML/PE-A + Troj/Gyepis-B
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1KR2NFM
JiangminTrojan/ShipUp.jp
AviraTR/Crypt.XPACK.Gen7
Antiy-AVLTrojan/Generic.ASMalwS.217
ArcabitTrojan.Lazy.D34042
ZoneAlarmTrojan.Win32.ShipUp.bok
MicrosoftTrojan:Win32/ShipUp.DSK!MTB
GoogleDetected
AhnLab-V3Trojan/Win32.Shipup.R58811
Acronissuspicious
McAfeePWS-Zbot-FATW!0D2171E5C52B
MAXmalware (ai score=82)
VBA32BScope.Malware-Cryptor.Hlux
MalwarebytesTrojan.FakeMS.ED
TrendMicro-HouseCallTROJ_KRYPTK.SML3
RisingTrojan.Kryptik!1.AB8B (CLASSIC)
YandexTrojan.GenAsa!z1P8Zet3YrQ
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.AYTK!tr
AVGWin32:Gepys-J [Trj]
Cybereasonmalicious.5c52bb
PandaTrj/Hexas.HEU

How to remove Lazy.213058?

Lazy.213058 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment