Malware

Lazy.318438 (B) removal tips

Malware Removal

The Lazy.318438 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.318438 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Creates a copy of itself
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Lazy.318438 (B)?


File Info:

name: 4364B7AE64242A9B1CF2.mlw
path: /opt/CAPEv2/storage/binaries/41b5a8fb64ca8415c4f50d071448dd0c1e51c778603a57b32935c870287a15f1
crc32: 3C435F56
md5: 4364b7ae64242a9b1cf296417a939a0e
sha1: a6136bf8451e5def7d642b7db9eb21a5188a5d70
sha256: 41b5a8fb64ca8415c4f50d071448dd0c1e51c778603a57b32935c870287a15f1
sha512: 9ad635b69397ce610d84fd860b9a9ba79ee4bdaff0c4a3127a951986023f9a10c2d4d58b51f41b56a8997ee53ca290a6f8466c4d88b25ef0224fce5bb3888db7
ssdeep: 12288:+vPH2kK2dYuD3zdxiUJhrTazSjlDa/ZScniF+G4F:+XWkK8Yu7zd4UJNTBa/ZScniF+d
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T16525171DE7A1438FC071563A691DF5A2A214E87FFBC2C321F0C875467D62B839A4A53B
sha3_384: b93fde92b7e768cc48724476e5fb2c948443aaa933b70d2037643b19ca2f39c3228cb89ea4317f70f97e994f079636b3
ep_bytes: d8d4eab488bd6e338d5c67a20f160f18
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Lazy.318438 (B) also known as:

BkavW32.AIDetectMalware
AVGWin32:Evo-gen [Trj]
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Lazy.318438
SkyhighBehavesLike.Win32.Generic.th
McAfeeTrojan-FVOQ!4364B7AE6424
Cylanceunsafe
ZillyaTrojan.Kryptik.Win32.3417729
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
K7GWTrojan ( 005a45ef1 )
Cybereasonmalicious.e64242
BitDefenderThetaGen:NN.ZexaF.36802.aLZ@ae6inqn
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.GIFY
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Razy-9856882-0
KasperskyVHO:Trojan.Win32.Copak.gen
BitDefenderGen:Variant.Lazy.318438
NANO-AntivirusTrojan.Win32.Selfmod.icgfyy
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Selfmod.ka
SophosMal/Inject-GJ
F-SecureHeuristic.HEUR/AGEN.1369103
VIPREGen:Variant.Lazy.318438
FireEyeGeneric.mg.4364b7ae64242a9b
EmsisoftGen:Variant.Lazy.318438 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Selfmod.awpr
VaristW32/Zusy.EM.gen!Eldorado
AviraHEUR/AGEN.1369103
MAXmalware (ai score=87)
Antiy-AVLTrojan/Win32.Kryptik.gify
Kingsoftmalware.kb.a.994
MicrosoftTrojan:Win32/Glupteba.MT!MTB
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
ArcabitTrojan.Lazy.D4DBE6
ZoneAlarmVHO:Trojan.Win32.Copak.gen
GDataWin32.Trojan.PSE.11XGYE9
GoogleDetected
AhnLab-V3Packed/Win.FJB.C5393480
Acronissuspicious
VBA32Trojan.Copak
ALYacGen:Variant.Lazy.318438
TACHYONTrojan/W32.Selfmod
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.BF57 (CLASSIC)
IkarusTrojan-Downloader.Win32.FakeAlert
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GIFQ!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudVirTool:Win/Kryptik.GIRH

How to remove Lazy.318438 (B)?

Lazy.318438 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment