Malware

Lazy.233168 information

Malware Removal

The Lazy.233168 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.233168 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Binary compilation timestomping detected

How to determine Lazy.233168?


File Info:

name: ED85B0C55BAFF4D6E8B0.mlw
path: /opt/CAPEv2/storage/binaries/fd50d018a952851bda3151502264939fe89fdbe8110e69e9a48f01c5216ca5fd
crc32: 0A389673
md5: ed85b0c55baff4d6e8b0f8c9a7cce99b
sha1: 89b241f2ee317c7dff73f9d5d2f4cf73017d3fe2
sha256: fd50d018a952851bda3151502264939fe89fdbe8110e69e9a48f01c5216ca5fd
sha512: 342406af4475f0d02e2ae889b5583e8a95c616739683e2006c63d9be9c3fefb513fdab06dc00c25001f284fe370ce13f1f06d025e5cfb19ce942d69bef94c0f1
ssdeep: 49152:C7uyPKEkUcSN5TQ2mtywR+xStOnu2zzg12D9HqzwTPttYX6a00zu52w:MPKEkGNW2m0E+8ouYzNUzwrtKKa
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14CB523C27165890BDCA95F71117109D443B28A022F96CFCE9DDD93EE0F63719DAC2AA3
sha3_384: 0989b158ff94bdbbcd165e5dd2731f606f7249f82ad111aaedbffe33068625afa00858116bedafe3d4e3f3ef2e4d6126
ep_bytes: ff250020400000000000000000000000
timestamp: 2042-05-15 02:06:29

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: Autoupdate
FileVersion: 1.0.0.0
InternalName: Autoupdate.exe
LegalCopyright: Copyright © 2021
LegalTrademarks:
OriginalFilename: Autoupdate.exe
ProductName: Autoupdate
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Lazy.233168 also known as:

BkavW32.AIDetectNet.01
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Variant.Lazy.233168
FireEyeGen:Variant.Lazy.233168
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
ALYacGen:Variant.Lazy.233168
CylanceUnsafe
SangforTrojan.Win32.Agent.Vxl7
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanPSW:Win32/OnLineGames.30068617
K7GWRiskware ( 0040eff71 )
CyrenW32/CsdiMonetize.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
Paloaltogeneric.ml
BitDefenderGen:Variant.Lazy.233168
AvastWin32:DropperX-gen [Drp]
EmsisoftGen:Variant.Lazy.233168 (B)
ComodoMalware@#2ucm0qyse2pzi
VIPREGen:Variant.Lazy.233168
TrendMicroTROJ_GEN.R002C0PGO22
McAfee-GW-EditionGenericRXQB-OE!ED85B0C55BAF
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Lazy.233168
GoogleDetected
Antiy-AVLTrojan/Generic.ASMalwS.813F
ArcabitTrojan.Lazy.D38ED0
MicrosoftTrojan:Win32/Tiggre!rfn
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.FU.C4731615
McAfeeGenericRXQB-OE!ED85B0C55BAF
MAXmalware (ai score=80)
VBA32Trojan.Wacatac
MalwarebytesTrojan.Downloader.MSIL.Generic
TrendMicro-HouseCallTROJ_GEN.R002C0PGO22
RisingTrojan.Generic/MSIL@AI.94 (RDM.MSIL:oOw50Pa47ytA2qJzrpEkEw)
IkarusTrojan-PWS.Win32.OnLineGames
MaxSecureTrojan.Malware.186933836.susgen
FortinetPossibleThreat
AVGWin32:DropperX-gen [Drp]
PandaTrj/Chgt.AD

How to remove Lazy.233168?

Lazy.233168 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment