Malware

Lazy.255821 (B) (file analysis)

Malware Removal

The Lazy.255821 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.255821 (B) virus can do?

  • Sample contains Overlay data
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Lazy.255821 (B)?


File Info:

name: E7BA87303D4AB0B5B60D.mlw
path: /opt/CAPEv2/storage/binaries/c34366d9191d3961cd28756b7efd2d87b1d032642c619d6a551556a2b347250a
crc32: 02EBDB48
md5: e7ba87303d4ab0b5b60d7656a8958864
sha1: 6928978bda640a7d050ccc235a354d63c2cc1be1
sha256: c34366d9191d3961cd28756b7efd2d87b1d032642c619d6a551556a2b347250a
sha512: 1f1af45dd4704058d5130d0626fdc2814d040ffbd7175a481f1e01aa02a0e4f539fd8c7ceff27c699455a0095a661e4b47e8d31ceed9cba92a1a5c96226b8cae
ssdeep: 6144:3s975es9SWGNTNYdMzATVkQNUO7q5S7UZ3UVt:cxks9TGNTCWsTGQ487QUVt
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T19554387BDD38F8D1C27E5CB46B91C700AB7261714B42638BE178C26DCE136E15E6AC26
sha3_384: d5d9798db0859c0ef8d2a7b5b91b94d40d626d3b56583169ba99367903affce9bd7d223e5ff92ae95363a4ffa803621a
ep_bytes: e848feffffc82000004c897c24f84883
timestamp: 2017-05-15 21:34:56

Version Info:

CompanyName: Microsoft Corporation
FileDescription: AppVDllSurrogate64
InternalName: AppVDllSurrogate
LegalCopyright: © 2015 Microsoft Corporation. All rights reserved.
LegalTrademarks: Microsoft® is a registered trademark of Microsoft Corporation.
OriginalFilename: AppVDllSurrogate64.exe
ProductName: Microsoft Application Virtualization (App-V)
FileVersion: 5.1.125.0
ProductVersion: 5.1.125.0
PrivateBuild: RTM (by sftbuild on MBAMR02BLD02)
Translation: 0x0409 0x04b0

Lazy.255821 (B) also known as:

MicroWorld-eScanGen:Variant.Lazy.255821
ClamAVWin.Trojan.Generic-9951842-0
FireEyeGen:Variant.Lazy.255821
VIPREGen:Variant.Lazy.255821
K7AntiVirusTrojan ( 0059aa0b1 )
K7GWTrojan ( 0059aa0b1 )
CyrenW64/Ipamor.A
SymantecML.Attribute.HighConfidence
ESET-NOD32Win64/Filecoder.GG
APEXMalicious
KasperskyVHO:Trojan-Ransom.Win32.Blocker.gen
BitDefenderGen:Variant.Lazy.255821
AvastWin64:Trojan-gen
Ad-AwareGen:Variant.Lazy.255821
EmsisoftGen:Variant.Lazy.255821 (B)
DrWebWin32.HLLP.Azov.2
TrendMicroRansom.Win64.AZVO.SMYXCJ5
GDataGen:Variant.Lazy.255821
JiangminTrojan.Blocker.urx
Antiy-AVLTrojan/Generic.ASBOL.C73A
ArcabitTrojan.Lazy.D3E74D
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
ALYacGen:Variant.Lazy.255821
MAXmalware (ai score=84)
MalwarebytesMalware.AI.1053266483
RisingRansom.Agent!8.6B7 (TFE:2:U9tOTBNOHOO)
IkarusTrojan-Ransom.FileCrypter
FortinetW64/Filecoder.GG!tr
AVGWin64:Trojan-gen

How to remove Lazy.255821 (B)?

Lazy.255821 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment