Malware

How to remove “Lazy.265716”?

Malware Removal

The Lazy.265716 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.265716 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Harvests cookies for information gathering
  • Adds itself to the Safe Mode boot to ensure its start

How to determine Lazy.265716?


File Info:

name: 30336C7F97148BACBB6F.mlw
path: /opt/CAPEv2/storage/binaries/dbf3ca4534f5cf0866e5e03c22475df6ed90efb88a7b2e64cfc650a6272443b4
crc32: 361EF131
md5: 30336c7f97148bacbb6f97017de56aeb
sha1: f373cf1fca38f7ea98fa991520d6bbd24119ff92
sha256: dbf3ca4534f5cf0866e5e03c22475df6ed90efb88a7b2e64cfc650a6272443b4
sha512: 10a932960cc40090494c0cc4148d98551e9df68b94c0c6d6e049d812d4865ac12b270b64fac6c99bb38602af1be6ebff75fd7a08ce88e7adb3dbcdc912377a52
ssdeep: 12288:GS/cGbZ+uSYduT8TJnHlDPo0WC814i83uVHZpxUuiotGMFBVdy+:GucGbEuS6TJnHlU0WC814iGuV5bi0G0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FBD48D55F843F2FBD15329BC4E7699D12660FA2028259CB773E68F3E1736E902C25B06
sha3_384: 2ff34111ce6eb7b14c87c3070ad5636bbab1aea4dcc397a9fd7de6eea374a3797dd70196449cf117e0661f34d794b5ac
ep_bytes: c60590f2440000b900604600ba046046
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Lazy.265716 also known as:

LionicTrojan.Win32.Babar.4!c
Elasticmalicious (high confidence)
McAfeeArtemis!30336C7F9714
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0059998a1 )
AlibabaTrojan:Win32/Filecoder.199de5da
Cybereasonmalicious.fca38f
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.OMK
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-PSW.Win32.Stealer.atgu
BitDefenderGen:Variant.Lazy.265716
MicroWorld-eScanGen:Variant.Lazy.265716
AvastWin32:Trojan-gen
TencentWin32.Trojan.Filecoder.Gmnw
Ad-AwareGen:Variant.Babar.116889
EmsisoftGen:Variant.Babar.116889 (B)
VIPREGen:Variant.Babar.116889
McAfee-GW-EditionBehavesLike.Win32.Ransomware.hh
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.30336c7f97148bac
SophosMal/Generic-S
WebrootW32.Malware.Gen
AviraTR/Downloader.Gen
MAXmalware (ai score=82)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitTrojan.Babar.D1C899
ZoneAlarmTrojan-PSW.Win32.Stealer.atgu
GDataGen:Variant.Babar.116889
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34796.KCW@aObayoo
ALYacGen:Variant.Babar.116889
VBA32BScope.Trojan.StartPage
CylanceUnsafe
TrendMicro-HouseCallTROJ_GEN.R002H09KI22
RisingRansom.Agent!8.6B7 (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Filecoder.OMK!tr.ransom
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Lazy.265716?

Lazy.265716 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment