Malware

Lazy.328293 (file analysis)

Malware Removal

The Lazy.328293 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.328293 virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Lazy.328293?


File Info:

name: 6373FBB393331B49566D.mlw
path: /opt/CAPEv2/storage/binaries/907a181682d2a654068b22dbe75c92bc0edb103ae20565daab35075f3e57427e
crc32: 53DC6E37
md5: 6373fbb393331b49566d76d07b6fc4ad
sha1: 06bb108efbb7704afb4cdb5e7d723467a1609332
sha256: 907a181682d2a654068b22dbe75c92bc0edb103ae20565daab35075f3e57427e
sha512: b714b584eb2e3c505def1aafff8bf56a1320d96539c4e477487a615d875130b740ea0f28303bf790fafaadd4b766879fa21e4f5c25058ef16029af1939bf4de2
ssdeep: 49152:kHajF4KbIt60kwlDNBgqeF+bq4TTow+lsghbyV8qXdTy:rR4Oy6twrNeshTWROV8qtm
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T127B5D00D23A51D47C6277B3FED2CC77B800169BD3A93D2B9318539AAB6623D4D902B74
sha3_384: 73de88946b2fd6e180443aa072fd1862cb9c4d367f8c1b4dce368f147d2344243f8e797408cc73d1e268285edd70f360
ep_bytes: 3d044bb06d6dcf37688cc6a6eac6ae1c
timestamp: 1975-06-24 00:00:00

Version Info:

0: [No Data]

Lazy.328293 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.328293
SkyhighBehavesLike.Win32.Sytro.vc
McAfeeTrojan-FVOQ!6373FBB39333
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Lazy.328293
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
BitDefenderGen:Variant.Lazy.328293
K7GWTrojan ( 005a45ef1 )
Cybereasonmalicious.efbb77
BitDefenderThetaGen:NN.ZexaF.36792.q!Z@aSJ4gId
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik_AGen.BGV
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Razy-9785185-0
KasperskyVHO:Trojan.Win32.Khalesi.gen
NANO-AntivirusTrojan.Win32.PackedDownloader.ijxqni
RisingTrojan.Kryptik!1.BF57 (CLASSIC)
TACHYONTrojan/W32.Selfmod
SophosTroj/Agent-BFEY
F-SecureHeuristic.HEUR/Patched.Ren
ZillyaTrojan.Generic.Win32.1139062
FireEyeGeneric.mg.6373fbb393331b49
EmsisoftGen:Variant.Lazy.328293 (B)
IkarusTrojan.Win32.Glupteba
VaristW32/Copak.E.gen!Eldorado
AviraHEUR/Patched.Ren
Antiy-AVLTrojan/Win32.Kryptik.GIFY
Kingsoftmalware.kb.a.939
MicrosoftTrojan:Win32/Glupteba.MT!MTB
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
ArcabitTrojan.Lazy.D50265
ZoneAlarmVHO:Trojan.Win32.Khalesi.gen
GDataWin32.Trojan.PSE.11YPVZ
GoogleDetected
AhnLab-V3Packed/Win.Generic.R565453
Acronissuspicious
VBA32Trojan.Copak
ALYacGen:Variant.Lazy.328293
MAXmalware (ai score=81)
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Genetic.gen
TencentTrojan.Win32.Selfmod.ka
YandexTrojan.Redcap!zbi6EFdgH7I
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:RATX-gen [Trj]
AvastWin32:RATX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Lazy.328293?

Lazy.328293 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment