Malware

Lazy.29532 removal tips

Malware Removal

The Lazy.29532 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.29532 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Lazy.29532?


File Info:

name: 25CA2CB1D664F51326AD.mlw
path: /opt/CAPEv2/storage/binaries/3223388000a49f60d6ce668ecc427797ae298b0ad0508355264e5a6ec62d9716
crc32: F99090C7
md5: 25ca2cb1d664f51326ad96ddb844e328
sha1: 1f3922508aa1f56ad55a09c9af4a1652e8c5bd68
sha256: 3223388000a49f60d6ce668ecc427797ae298b0ad0508355264e5a6ec62d9716
sha512: b5b1f4d6d6817bf710eb14d72e4796836fbdfa7afb27da4fe5cc86e7d77faeb5e10125f8fa1e7b37d0511765ffe716e4ac1fe6628f6797027b6ada9538d4fe8c
ssdeep: 196608:qswCcuSleqfOYE3T2V5ouujUY3zvmSLhmZoeMRnTPTzc:qsVcBxgT27fY3zvxLQkZD3c
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DBA63383786F44F2DB011C76683926F4EC756C74AB15C58F47A87E98F9310D0BEB12AA
sha3_384: 31729eceb460bd7390295f4a4e008a2cfcb21b67d6cf96da81d2611d7e8dddb184e37a3b450d309dfce84747470561b8
ep_bytes: e8a4040000e988feffff3b0d68e64300
timestamp: 2021-04-07 14:39:21

Version Info:

0: [No Data]

Lazy.29532 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.25ca2cb1d664f513
McAfeeArtemis!25CA2CB1D664
K7AntiVirusRiskware ( 00584baa1 )
BitDefenderGen:Variant.Lazy.29532
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.08aa1f
SymantecTrojan.Gen.MBT
APEXMalicious
ClamAVWin.Packed.Dorifel-9892630-0
AlibabaRansom:Win32/FileCrypter.0315440b
EmsisoftGen:Variant.Lazy.29532 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SophosGeneric ML PUA (PUA)
IkarusTrojan-Ransom.FileCrypter
AviraHEUR/AGEN.1145315
GridinsoftRansom.Win32.Sabsik.sa
GDataGen:Variant.Lazy.29532
CynetMalicious (score: 99)
ALYacGen:Variant.Lazy.29532
MAXmalware (ai score=88)
SentinelOneStatic AI – Malicious SFX
FortinetMalicious_Behavior.SB
AVGWin64:Malware-gen
AvastWin64:Malware-gen

How to remove Lazy.29532?

Lazy.29532 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment