Malware

Lazy.298975 removal

Malware Removal

The Lazy.298975 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.298975 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Lazy.298975?


File Info:

name: E4459E057E1D67C0776E.mlw
path: /opt/CAPEv2/storage/binaries/aa5255074f5d8860421f0ee1e9d98ec745416f36caeb3ef62a9bdadb9068e2b5
crc32: 9F680C97
md5: e4459e057e1d67c0776e23c72ae0ace6
sha1: eb30d326d1d161512e11825ddca062dc8d0243dd
sha256: aa5255074f5d8860421f0ee1e9d98ec745416f36caeb3ef62a9bdadb9068e2b5
sha512: b8591c2c02b2051491957cc1d5841b763f80723a2eeed1a4038e68889f4fc9db9127d0c7361eb4a7466cb4021046050f6758fc72cfe578557f7f016c22034840
ssdeep: 1536:FZgOPWiOJxpqjHvnKqKP7esaUrhaI77bu+NOmIgaQ0:vWiOCHAPa8aIXOKc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B96312A2693F7B48C7E74FF4D0AE9B82A867F340176B814F0EE56C9013D4AF535A2406
sha3_384: 31ea0f22dfc668dca82dc9bbbe5fd5d348e5a0fce4efc5276d6de060c459ac16e2a389dda78e6a162820235a2eacf927
ep_bytes: 60be156041008dbeebaffeff5783cdff
timestamp: 2007-02-03 22:20:18

Version Info:

InternalName: Pwdiejn
FileVersion: 853
CompanyName: BJ SOFTWIN MDF
FileDescription: Pwdiejn Klhkb Hkqjjwcfb
LegalCopyright: Copyright © Pwdiejn Software 2000-2011
OriginalFilename: Pwdiejn.exe
ProductName: Pwdiejn Klhkb Hkqjjwcfb
ProductVersion: 10.2
qVjmxD: C5s8IG1XQ
8UaPEB: p4oIFvO
icc4dQ: 2XrFy5Aa
BleJG: 37krBb
hKJIpDXbi3: 4UrMPAy61g
5yVWB65: YlXYTIldyB
eBYYmbDVfp: vbMPXRS
liKka8g: T8uywTH
jxLig1: uu6hRa
DnwpPpk2: mPQop
Translation: 0x0409 0x04e4

Lazy.298975 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lkrK
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Lazy.298975
ClamAVWin.Trojan.Shiz-1127
McAfeeArtemis!E4459E057E1D
ZillyaBackdoor.Shiz.Win32.659
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( f1000f011 )
AlibabaBackdoor:Win32/Obfuscator.2a990f87
K7GWTrojan ( f1000f011 )
Cybereasonmalicious.57e1d6
BitDefenderThetaGen:NN.ZexaF.36164.emKfa0Md93pi
CyrenW32/Oficla.AR.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.NHE
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Shiz.drv
BitDefenderGen:Variant.Lazy.298975
NANO-AntivirusTrojan.Win32.Agent.cezod
SUPERAntiSpywareTrojan.Agent/Gen-Falprod[Cont]
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.114add65
SophosMal/Zbot-CX
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Hottrend.46
VIPREGen:Variant.Lazy.298975
TrendMicroTROJ_KRYPTK.SMCM
McAfee-GW-EditionW32/Pinkslipbot.gen.as
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.e4459e057e1d67c0
EmsisoftGen:Variant.Lazy.298975 (B)
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Lazy.298975
JiangminBackdoor/Shiz.anb
WebrootW32.Trojan.Gen
AviraTR/Dropper.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan[Backdoor]/Win32.Shiz
XcitiumMalware@#1typ6imf3b1h9
ArcabitTrojan.Lazy.D48FDF
ViRobotBackdoor.Win32.A.Shiz.70144[UPX]
ZoneAlarmBackdoor.Win32.Shiz.drv
MicrosoftTrojanDropper:Win32/Bamital.L
GoogleDetected
VBA32BScope.Backdoor.Datpatcher.5523
ALYacGen:Variant.Lazy.298975
TACHYONBackdoor/W32.Shiz.128000
Cylanceunsafe
PandaBck/Qbot.AO
TrendMicro-HouseCallTROJ_KRYPTK.SMCM
RisingMalware.Undefined!8.C (TFE:5:1NdYLW2cfcJ)
YandexBackdoor.Shiz!+tcZlRs/jRQ
IkarusVirus.Worm.Pakes
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Bamital.FA!tr
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS

How to remove Lazy.298975?

Lazy.298975 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment