Malware

Lazy.214397 removal tips

Malware Removal

The Lazy.214397 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.214397 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Lazy.214397?


File Info:

name: A5CC611F3142A9F7051D.mlw
path: /opt/CAPEv2/storage/binaries/370fd261f8778121b03d2af821b89ba2a52616b5715a1420e3ca0632f255583e
crc32: B351CC5F
md5: a5cc611f3142a9f7051d02ba55c9e83a
sha1: 0bc93859a8bf24641152c320018c625b33bca3bf
sha256: 370fd261f8778121b03d2af821b89ba2a52616b5715a1420e3ca0632f255583e
sha512: 1f5dddcbf67e7f02b8338608f377ae861293394e821dfaf4b5f8d37b493783b1408276e86af6c9c573be2dc13cd19f4131770ee93b78b0c337794aac5da49902
ssdeep: 6144:1D6/5rWXrT3UzeQpH9OUNHhCdYOuJyUmyX4HA6V2pMW4tNlZpl1Gpo2cAEWsXrv9:1D6OyhpH9NHhgYOuJYbHlV2p4Njv4poT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E684011FE85AA78BCE6612FF1DA094A803F6DC128A41E158F42D7A4FCD5FD7C4814B98
sha3_384: 0231bb3a26f7388c6dc8dcd6bf58de0f5b9a28322d9a46ebc663c52272edfa76c83b15a16cfe1326bda40fe83ff86091
ep_bytes: e8dc0b0000e8f6ffffffa3853040006a
timestamp: 2004-09-06 00:00:35

Version Info:

Comments:
CompanyName: HP Corp
FileDescrsiption: calc.exe
FileVersion: 6.3.3.1
InternalName: calc.exe
LegalCopyright: Copyright (C) 2011
LegalTrademarks: Legal
OriginalFilename: calc.exe
PrivateBuild:
ProductName: calc.exe
ProductVersion: 6.3.3.1
SpecialBuild:
Translation: 0x0800 0x0026

Lazy.214397 also known as:

BkavW32.AIDetect.malware2
tehtrisGeneric.Malware
DrWebTrojan.PWS.Panda.5182
MicroWorld-eScanGen:Variant.Lazy.214397
FireEyeGeneric.mg.a5cc611f3142a9f7
CAT-QuickHealTrojanDownloader.Upatre.A5
ALYacGen:Variant.Lazy.214397
CylanceUnsafe
VIPREGen:Variant.Lazy.214397
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0040f6bd1 )
K7GWTrojan-Downloader ( 0040f6bd1 )
Cybereasonmalicious.f3142a
BitDefenderThetaAI:Packer.3C6996C91E
VirITTrojan.Win32.Banker.ZC
CyrenW32/A-814d4d13!Eldorado
SymantecTrojan.Zbot!gen71
Elasticmalicious (high confidence)
ESET-NOD32Win32/Spy.Zbot.AAU
APEXMalicious
ClamAVWin.Trojan.Zbot-58345
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Lazy.214397
NANO-AntivirusTrojan.Win32.Zbot.cqivpp
SUPERAntiSpywareTrojan.Agent/Gen-Spy
AvastWin32:Crypt-QFB [Trj]
TencentMalware.Win32.Gencirc.10c2a8c0
Ad-AwareGen:Variant.Lazy.214397
TACHYONTrojan-Spy/W32.ZBot.387072.AK
EmsisoftGen:Variant.Lazy.214397 (B)
ComodoTrojWare.Win32.TrojanDownloader.Waski.AOP@6axqm9
ZillyaTrojan.Zbot.Win32.143473
TrendMicroTSPY_ZBOT.SMJ29
McAfee-GW-EditionBehavesLike.Win32.Sytro.fh
Trapminemalicious.high.ml.score
SophosML/PE-A + Troj/Agent-AEUD
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Zbot.dycq
WebrootW32.InfoStealer.Zeus
GoogleDetected
AviraTR/Agent.38707258
Antiy-AVLTrojan/Generic.ASMalwS.31
MicrosoftPWS:Win32/Zbot!GO
GDataGen:Variant.Lazy.214397
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.R88085
McAfeeDownloader-FWT!A5CC611F3142
MAXmalware (ai score=83)
VBA32TrojanSpy.Zbot
MalwarebytesTrojan.Email
TrendMicro-HouseCallTSPY_ZBOT.SMJ29
RisingDownloader.Waski!8.184 (TFE:2:arVdPoy5dsR)
YandexTrojanSpy.Zbot!3KoKt3XcZsI
IkarusTrojan-PWS.Win32.Zbot
FortinetW32/Agent.AEUD!tr
AVGWin32:Crypt-QFB [Trj]
PandaTrj/WLT.A
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Lazy.214397?

Lazy.214397 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment