Malware

Lazy.326537 removal guide

Malware Removal

The Lazy.326537 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.326537 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Lazy.326537?


File Info:

name: 9D016AC17B6BC0671C60.mlw
path: /opt/CAPEv2/storage/binaries/d62808190c293a09518aff7d7613b0b8eb69da0ab5ee676f482bc3e85efd6322
crc32: C3997B26
md5: 9d016ac17b6bc0671c608760967abb1f
sha1: 892437088a0eb31f66b519022e394a176a7f94d0
sha256: d62808190c293a09518aff7d7613b0b8eb69da0ab5ee676f482bc3e85efd6322
sha512: 1e0e86d8dfb6ee85abef12dc50b5e18ffc6d25a8423ad2644dc576d3148d7de2dc699ab67159f3ac01cd00366bfea019a7d9e9d8a939af4048511ac001dcc39a
ssdeep: 3072:4L4KwghbcuxAKfRBYDu7aQMLCSwRlTjDE6jOcCP6a5trOFOsGmmjQNQK9jH1f7ED:o4bcxxAKJqDuvLlTH1070F97Vw/XcdU
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T17154AF29B74E2BB1F68603FD360E05D2E6372D7D2E794E5674A4802C13E293463BD7A1
sha3_384: df4eb2d012e695ccde793fb10f3ef177d7ce44728a8801d7ef60d9744f917150bf9b0e1f82a945b157df5a7025fd6aa1
ep_bytes: 9e6f33c6ce06b741cbe7bed0d9a5d66a
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Lazy.326537 also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Lazy.326537
SkyhighBehavesLike.Win32.Generic.dh
McAfeeTrojan-FVOQ!9D016AC17B6B
MalwarebytesCrypt.Trojan.MSIL.DDS
ZillyaTrojan.Kryptik.Win32.4097266
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
BitDefenderGen:Variant.Lazy.326537
K7GWTrojan ( 005a45ef1 )
CrowdStrikewin/malicious_confidence_100% (D)
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.GIFY
APEXMalicious
ClamAVWin.Packed.Zpack-10001780-0
KasperskyHEUR:Trojan.Win32.Copak.pef
NANO-AntivirusTrojan.Win32.Selfmod.iwyqke
RisingTrojan.Kryptik!1.B34D (CLASSIC)
TACHYONTrojan/W32.Selfmod
SophosMal/Inject-GJ
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.PackedENT.123
VIPREGen:Variant.Lazy.326537
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.9d016ac17b6bc067
EmsisoftGen:Variant.Lazy.326537 (B)
IkarusTrojan.Win32.Glupteba
JiangminTrojan.Copak.cpjf
GoogleDetected
AviraTR/Crypt.XPACK.Gen
VaristW32/Kryptik.CIN.gen!Eldorado
Antiy-AVLTrojan/Win32.Kryptik.GIRH
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Win32/Glupteba.MT!MTB
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
ArcabitTrojan.Lazy.D4FB89
ZoneAlarmHEUR:Trojan.Win32.Copak.pef
GDataGen:Variant.Lazy.326537
CynetMalicious (score: 100)
AhnLab-V3Packed/Win.FJB.C5394144
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36792.r8Z@a4kX8Mg
ALYacGen:Variant.Lazy.326537
MAXmalware (ai score=82)
DeepInstinctMALICIOUS
VBA32Trojan.Khalesi
Cylanceunsafe
PandaTrj/Genetic.gen
TencentTrojan.Win32.Copak.kf
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.204156042.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.88a0eb
AvastWin32:Evo-gen [Trj]

How to remove Lazy.326537?

Lazy.326537 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment