Malware

Lazy.328293 removal guide

Malware Removal

The Lazy.328293 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.328293 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Lazy.328293?


File Info:

name: D33A0E5105F011622B47.mlw
path: /opt/CAPEv2/storage/binaries/c4fdbc592780801dc4b5b11a848683d58e4987869434c1f19fbce46c9ae7faa0
crc32: 571A61B3
md5: d33a0e5105f011622b477f46ad30238d
sha1: 1f9557384cf6476f94e0bf4ecfc14a120b77ed69
sha256: c4fdbc592780801dc4b5b11a848683d58e4987869434c1f19fbce46c9ae7faa0
sha512: f98599779bbf87fa75238034ba6e6f211f09439398feb7842d6e2c2903f858be837b48a9dab346624a980ecea99627583de1b268ef3c01040c04f2385f4e6263
ssdeep: 6144:BvFTbcmM293lQcsAufKQm6/hMxTTBt4JD2wABbxxJa/YESa1p84:BtTbcmjlQcs2WMJb492jVDa/ZSa1p84
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T13815395C266A36B3C5491277AA3EBAA44093FDF86613F272304B7D4FF6153A27442E70
sha3_384: de93d127499c0d80582898ea719b0220cc3d5350bf631a4477fc1d4d651e70a97cb8c1bda641c255b840612f3c94985e
ep_bytes: 5754fdc4073d794302dc70d280961868
timestamp: 1974-02-09 00:00:00

Version Info:

0: [No Data]

Lazy.328293 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Copak.4!c
tehtrisGeneric.Malware
DrWebTrojan.Siggen12.43572
MicroWorld-eScanGen:Variant.Lazy.328293
FireEyeGeneric.mg.d33a0e5105f01162
SkyhighBehavesLike.Win32.Trojan.dm
McAfeeTrojan-FVOQ!D33A0E5105F0
Cylanceunsafe
ZillyaTrojan.Generic.Win32.413820
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/Glupteba.8ec35a5a
K7GWTrojan ( 005a14d51 )
K7AntiVirusTrojan ( 005a45ef1 )
BitDefenderThetaGen:NN.ZexaF.36802.58X@aCXYzHj
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik_AGen.BFL
APEXMalicious
ClamAVWin.Packed.Dridex-9860931-1
KasperskyHEUR:Trojan.Win32.Selfmod.gen
BitDefenderGen:Variant.Lazy.328293
NANO-AntivirusTrojan.Win32.Kryptik.fgvkbr
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Selfmod.ka
TACHYONTrojan/W32.Selfmod
EmsisoftGen:Variant.Lazy.328293 (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
VIPREGen:Variant.Lazy.328293
Trapminemalicious.high.ml.score
SophosMal/Inject-GJ
IkarusTrojan.Win32.Glupteba
JiangminTrojan.Generic.cvalq
GoogleDetected
AviraTR/Crypt.ZPACK.Gen
VaristW32/Trojan.MJSE-7842
Antiy-AVLTrojan/Win32.Kryptik.gify
KingsoftWin32.HeurC.KVMH008.a
MicrosoftTrojan:Win32/Glupteba.MT!MTB
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
ArcabitTrojan.Lazy.D50265
ZoneAlarmUDS:Trojan.Win32.Selfmod.gen
GDataWin32.Trojan.PSE.11XGYE9
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.OB.C5394211
Acronissuspicious
ALYacGen:Variant.Lazy.328293
MAXmalware (ai score=83)
VBA32Trojan.Copak
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B34D (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.105f01
DeepInstinctMALICIOUS
alibabacloudVirTool:Win/Obfuscate.SMC.DYN(dyn)

How to remove Lazy.328293?

Lazy.328293 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment