Malware

Lazy.239194 (B) information

Malware Removal

The Lazy.239194 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.239194 (B) virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Lazy.239194 (B)?


File Info:

name: 61C7A7C40EC2E74E2635.mlw
path: /opt/CAPEv2/storage/binaries/2be94736d9fd156949ec8550c736f1e9ae7c36d99fbaf5a0c88043dbb21925a2
crc32: D2933670
md5: 61c7a7c40ec2e74e26353fe79251e3eb
sha1: e0961d6350176fdff9e33bbf341f8011ad543ef9
sha256: 2be94736d9fd156949ec8550c736f1e9ae7c36d99fbaf5a0c88043dbb21925a2
sha512: 7e90b2b6d7cb0dbffbc10167b345efd81ead808cc0f2f49a5fca6bc4b7fd778aafdb7b4723aabb8a56aab86b1cbdd453f56c14e6ccbe713b535524a041082b63
ssdeep: 12288:pexrUAPrkUyLShsVhU7PG8iwP2ch5IOIH7MT5yndxh/uz2VqGGXi5Cws1fwb:pexrUAPIUyLShsVZDH7MTOdxhNqkCw
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18A258C203AD0857EEDE210BB46EFB535467DB0B0372506CB06C897EEC7206E56FB6586
sha3_384: c83487189411824082c10fddb10025a62cfb8e1eb89b9fc975b8c6f4928f3034737addec0e185be3dddafc03b4d3accb
ep_bytes: e92c700300e99d330800e985eb0700e9
timestamp: 2022-09-01 10:10:26

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Application Virtualization Injector
FileVersion: 10.0.19041.1202 (WinBuild.160101.0800)
InternalName: mavinject32.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: mavinject32.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 10.0.19041.1202
Translation: 0x0409 0x04b0

Lazy.239194 (B) also known as:

DrWebTrojan.PWS.Steam.28157
MicroWorld-eScanGen:Variant.Lazy.239194
FireEyeGen:Variant.Lazy.239194
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/GenKryptik_AGen.KJ
KasperskyHEUR:Backdoor.Win32.Mokes.gen
BitDefenderGen:Variant.Lazy.239194
AvastCrypterX-gen [Trj]
Ad-AwareGen:Variant.Lazy.239194
EmsisoftGen:Variant.Lazy.239194 (B)
VIPREGen:Variant.Doina.42548
McAfee-GW-EditionPacked-GEP!61C7A7C40EC2
GDataGen:Variant.Lazy.239194
MAXmalware (ai score=89)
ArcabitTrojan.Lazy.D3A65A
ZoneAlarmHEUR:Backdoor.Win32.Mokes.gen
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ALYacGen:Variant.Doina.42548
MalwarebytesTrojan.Crypt.Generic
RisingBackdoor.Mokes!8.619 (TFE:5:SIaBxA2skqJ)
AVGCrypterX-gen [Trj]
PandaTrj/Genetic.gen

How to remove Lazy.239194 (B)?

Lazy.239194 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment