Malware

What is “Lazy.224723”?

Malware Removal

The Lazy.224723 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.224723 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the Fareit malware family
  • Harvests cookies for information gathering
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed mail clients

How to determine Lazy.224723?


File Info:

name: AE1D5FA7880BA3C2E323.mlw
path: /opt/CAPEv2/storage/binaries/5ccc78835d9926d8009c1bdc271198328279f1d33aac021d84b2aac9b003ce84
crc32: 5111756A
md5: ae1d5fa7880ba3c2e3235b854b8f9188
sha1: 0b83a976c1923d299eff793616a44b3be1524d09
sha256: 5ccc78835d9926d8009c1bdc271198328279f1d33aac021d84b2aac9b003ce84
sha512: a2e6a0609b1c558f23a65f6616e200bb5c9d60979a56f609ffdac382ad01e0d9a67bcc688149b2c8927d8bab813f1c34a1fd7709198456511aab0493af743f6a
ssdeep: 3072:cLxOjw0j5DTvnYjQ8j5s+jZbQZtEkvW3Bi9WpWfbIH:cLxSjRTgdjuCbQMkeGoWfMH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T101144917B545411BE52F61F1E65F8E912086BEDE1224C28E26E6BF1EC0F73701127BAB
sha3_384: a2e04d210330074634379ec8bcc6dbe1ee8528118db64d8940652a4435b3f679b0987b3e148b1349587aa05f3804c4fd
ep_bytes: 558bec68007f00006a00ff15aca04000
timestamp: 2013-01-14 20:21:07

Version Info:

CompanyName: Корпорация Майкрософт
FileDescription: Звукозапись
FileVersion: 5.1.2600.5512 (xpsp.080413-0845)
InternalName: soundrec.exe
LegalCopyright: © Корпорация Майкрософт. Все права защищены.
OriginalFilename: sndrec32.exe
ProductName: Операционная система Microsoft® Windows®
ProductVersion: 5.1.2600.5512
Translation: 0x0419 0x04b0

Lazy.224723 also known as:

BkavW32.AIDetect.malware2
tehtrisGeneric.Malware
DrWebTrojan.PWS.Panda.3414
MicroWorld-eScanGen:Variant.Lazy.224723
FireEyeGeneric.mg.ae1d5fa7880ba3c2
CAT-QuickHealTrojanPWS.Zbot.Gen
ALYacGen:Variant.Lazy.224723
CylanceUnsafe
VIPREGen:Variant.Lazy.224723
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0040f0ce1 )
K7GWTrojan-Downloader ( 0040f0ce1 )
Cybereasonmalicious.7880ba
BitDefenderThetaGen:NN.ZexaF.34698.lG2@a4L7!2vc
CyrenW32/Zbot.GX.gen!Eldorado
SymantecPacked.Generic.406
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.ASCD
APEXMalicious
TrendMicro-HouseCallTSPY_FAREIT.SMJD
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Lazy.224723
NANO-AntivirusTrojan.Win32.Tepfer.bhkkkw
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AvastWin32:Karagany
TencentMalware.Win32.Gencirc.1201d258
Ad-AwareGen:Variant.Lazy.224723
EmsisoftGen:Variant.Lazy.224723 (B)
ComodoTrojWare.Win32.Spy.ZBot.EB@4uei1b
TrendMicroTSPY_FAREIT.SMJD
McAfee-GW-EditionPWS-Zbot.gen.xd
Trapminemalicious.high.ml.score
SophosML/PE-A + Troj/Zbot-DPP
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Generic.arqpx
GoogleDetected
AviraTR/PSW.Zbot.mal
MAXmalware (ai score=83)
MicrosoftPWS:Win32/Fareit
GDataGen:Variant.Lazy.224723
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win32.Zbot.R47869
McAfeePWS-Zbot.gen.xd
TACHYONTrojan-PWS/W32.Tepfer.190600
VBA32BScope.TrojanRansom.Shade
MalwarebytesTrojan.Zbot
RisingTrojan.Agent!1.66F3 (CLASSIC)
YandexTrojan.GenAsa!4ivdvQdz5b8
IkarusTrojan-PWS.Win32.Zbot
FortinetW32/Zbot.AAU!tr
AVGWin32:Karagany
PandaTrj/Hexas.HEU
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Lazy.224723?

Lazy.224723 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment