Malware

Lazy.259675 (B) removal

Malware Removal

The Lazy.259675 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.259675 (B) virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Lazy.259675 (B)?


File Info:

name: E30458620FD7C4CEBFCE.mlw
path: /opt/CAPEv2/storage/binaries/4489652c7dad7ec4003df514f602a8b585e88f6dfc07391c18d0bbb39d17732f
crc32: 3AED27D4
md5: e30458620fd7c4cebfce54e63e800eaf
sha1: 62bb4ba95a2151fa11a251c8e916fe417b1f56d3
sha256: 4489652c7dad7ec4003df514f602a8b585e88f6dfc07391c18d0bbb39d17732f
sha512: be094641a9e80bb4315e7477095c6b1ae9f7a8ea1cc775d52766ead7f3bee26776597988874166487866e76eabb3f6d0871fb9d63cd3d7f46eae73a32a00230a
ssdeep: 6144:BNQvYTo9MylvPs9gGhzLOYKLLZGpWc8KFksJ09xJTtP7/F30s3Yo0EMEJUiqYk:BNQv9vPs9gozDC3c8KF5i9MS/0EMEJ6l
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T19CE4D451ABA449B1F0B299348975866C9B727C55CD23CE0F20959EDEFFF39808D24B32
sha3_384: a5cbd7c535e98b4f6604b1ac50dd3d19d032921e0c4bfe96eb8a129b4feb9f1f2e89609732b2170414e58a0a461e6d00
ep_bytes: e848feffffc82000004c897c24f84883
timestamp: 2015-07-30 12:30:47

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Office Multi-Msi ActiveDirectory Deployment Tool.
FileVersion: 16.0.4266.1001
InternalName: odeploy.exe
LegalTrademarks1: Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windows® is a registered trademark of Microsoft Corporation.
OriginalFilename: odeploy.exe
ProductName: Microsoft Office 2016
ProductVersion: 16.0.4266.1001
MOSEVersion: BETA
Translation: 0x0000 0x04e4

Lazy.259675 (B) also known as:

MicroWorld-eScanGen:Variant.Lazy.259675
FireEyeGen:Variant.Lazy.259675
ALYacGen:Variant.Lazy.259675
CyrenW64/Ipamor.A
ESET-NOD32Win64/Filecoder.GG
BitDefenderGen:Variant.Lazy.259675
AvastWin64:Trojan-gen
Ad-AwareGen:Variant.Lazy.259675
EmsisoftGen:Variant.Lazy.259675 (B)
VIPREGen:Variant.Lazy.259675
GDataGen:Variant.Lazy.259675
JiangminTrojan.Blocker.urx
GoogleDetected
MAXmalware (ai score=83)
ArcabitTrojan.Lazy.D3F65B
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Trojan/Win.Generic.R532644
MalwarebytesRansom.Azov
FortinetW64/Filecoder.GG!tr
AVGWin64:Trojan-gen

How to remove Lazy.259675 (B)?

Lazy.259675 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment