Malware

Lazy.255821 removal guide

Malware Removal

The Lazy.255821 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.255821 virus can do?

  • Sample contains Overlay data
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Lazy.255821?


File Info:

name: C9E49F389C783DB305A9.mlw
path: /opt/CAPEv2/storage/binaries/0806573c1accd9b6277a379be046aa5038451b8c79e0d2566c33306f427939f1
crc32: C94F7FD6
md5: c9e49f389c783db305a9d63c0140e0f0
sha1: e5b208cbf5882b9d92d99f59fc12624c77960eb0
sha256: 0806573c1accd9b6277a379be046aa5038451b8c79e0d2566c33306f427939f1
sha512: 3813481aa3991025fc1e76617dacbde83ce91d0372ea4fec2cb50efe5380b00c247b8a0d6615d5d3e43b272534cc21f3a0154afadf0f85fcacc9bc0de3a892e5
ssdeep: 6144:3797ems9gWGNTNYdMzATVkQNUO7q5X1PnNwN:LxNs99GNTCWsTGQ4LPNC
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T1E654397BDD38F8D2C27E5CB4A7A0C700AB3261714B42638BE179C26DDD136E15E69C26
sha3_384: 0d9b914ebe2f95f1b416f444d1ba6adb90f313310d774fc452e9d147fffc7ad679382cbf369804180169aeb09546fb80
ep_bytes: e848feffffc82000004c897c24f84883
timestamp: 2017-05-15 21:34:56

Version Info:

CompanyName: Microsoft Corporation
FileDescription: AppVDllSurrogate64
InternalName: AppVDllSurrogate
LegalCopyright: © 2015 Microsoft Corporation. All rights reserved.
LegalTrademarks: Microsoft® is a registered trademark of Microsoft Corporation.
OriginalFilename: AppVDllSurrogate64.exe
ProductName: Microsoft Application Virtualization (App-V)
FileVersion: 5.1.125.0
ProductVersion: 5.1.125.0
PrivateBuild: RTM (by sftbuild on MBAMR02BLD02)
Translation: 0x0409 0x04b0

Lazy.255821 also known as:

LionicTrojan.Win32.Crypmodng.tsaK
MicroWorld-eScanGen:Variant.Lazy.255821
McAfeeArtemis!C9E49F389C78
CylanceUnsafe
K7AntiVirusTrojan ( 0059aa0b1 )
AlibabaTrojan:Win64/Filecoder.1f37bd46
K7GWTrojan ( 0059a88d1 )
CyrenW64/Ipamor.A
SymantecML.Attribute.HighConfidence
ESET-NOD32Win64/Filecoder.GG
APEXMalicious
ClamAVWin.Trojan.Generic-9951842-0
KasperskyUDS:Trojan-Ransom.Win32.Blocker
BitDefenderGen:Variant.Lazy.255821
AvastWin64:Trojan-gen
Ad-AwareGen:Variant.Lazy.255821
EmsisoftGen:Variant.Lazy.255821 (B)
VIPREGen:Variant.Lazy.255821
FireEyeGen:Variant.Lazy.255821
SophosMal/Generic-S
GDataGen:Variant.Lazy.255821
JiangminTrojan.Blocker.urx
GoogleDetected
MAXmalware (ai score=84)
ArcabitTrojan.Lazy.D3E74D
MicrosoftTrojan:Script/Phonzy.A!ml
ALYacGen:Variant.Lazy.255821
MalwarebytesMalware.AI.1053266483
RisingRansom.Agent!8.6B7 (TFE:2:U9tOTBNOHOO)
IkarusTrojan-Ransom.FileCrypter
FortinetW64/Filecoder.GG!tr
AVGWin64:Trojan-gen
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Lazy.255821?

Lazy.255821 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment