Malware

Lazy.328293 removal tips

Malware Removal

The Lazy.328293 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.328293 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Lazy.328293?


File Info:

name: 015B7BBDD465BFB68377.mlw
path: /opt/CAPEv2/storage/binaries/5026695a8749137b6badc86ba3e1e69592b23a45b48c38c0e04ed5360249b37a
crc32: 64F33E42
md5: 015b7bbdd465bfb683778b73af53781a
sha1: f3a97d71545d44015d15d7ead5cbab086addbd7c
sha256: 5026695a8749137b6badc86ba3e1e69592b23a45b48c38c0e04ed5360249b37a
sha512: 6532119f4ffd70bc628a00c05fad7fd7d8f23ab7fd74b5e92759891db3bee431ccb7cea1dbe7d12bbba2ff5bf037e2bd69130a93d4152d274a9d209d654854ef
ssdeep: 24576:Nzu4eSP8gQZj/P4jY7sAUIHPEE4LdBWWNJA7gUa/ZSTeF+77LX:Nu4eSPbQZNQAH/WNxUgqeF+bX
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T17325D01D3A2520CBD0AE1275EC6DDA5A50A32C3EEAB3D6B73C16B653F8693C45506F30
sha3_384: a07eed199605a16b3cba9f519d6cdb6a8eeaede9db26baf16f23d2026ea7a981fe405dba5237d065b040f281a6127786
ep_bytes: 81b57dbfd1dcf938d43df0a956779813
timestamp: 1975-06-24 00:00:00

Version Info:

0: [No Data]

Lazy.328293 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Khalesi.4!c
Elasticmalicious (high confidence)
ClamAVWin.Packed.Razy-9836307-0
FireEyeGeneric.mg.015b7bbdd465bfb6
SkyhighBehavesLike.Win32.HLLP.dc
McAfeeTrojan-FVOQ!015B7BBDD465
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Kryptik.Win32.3117393
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0001b3411 )
BitDefenderGen:Variant.Lazy.328293
K7GWTrojan ( 0001b3411 )
Cybereasonmalicious.1545d4
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik_AGen.BGV
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Copak.aixov
ViRobotTrojan.Win.Z.Lazy.983041.KHF
MicroWorld-eScanGen:Variant.Lazy.328293
RisingTrojan.Kryptik!1.B34D (CLASSIC)
SophosTroj/Agent-BFEY
F-SecureHeuristic.HEUR/AGEN.1369103
DrWebTrojan.Siggen22.588
VIPREGen:Variant.Lazy.328293
TrendMicroTROJ_GEN.R002C0DKC23
EmsisoftGen:Variant.Lazy.328293 (B)
SentinelOneStatic AI – Malicious PE
VaristW32/Trojan.ULNO-1867
AviraHEUR/AGEN.1369103
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.Kryptik.GIFY
Kingsoftmalware.kb.a.985
MicrosoftTrojan:Win32/Glupteba.MT!MTB
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
ArcabitTrojan.Lazy.D50265
ZoneAlarmTrojan.Win32.Copak.aixov
GDataWin32.Trojan.PSE.11YPVZ
GoogleDetected
AhnLab-V3Packed/Win.Generic.R565453
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36792.88Z@aSJ4gId
ALYacGen:Variant.Lazy.328293
TACHYONTrojan/W32.Selfmod
DeepInstinctMALICIOUS
VBA32Trojan.Copak
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DKC23
TencentTrojan.Win32.Selfmod.ka
YandexTrojan.Kryptik_AGen!dWL+2v8FeDQ
IkarusTrojan.Win32.Glupteba
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Lazy.328293?

Lazy.328293 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment