Malware

How to remove “Lazy.331927”?

Malware Removal

The Lazy.331927 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.331927 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Attempts to access Bitcoin/ALTCoin wallets
  • Touches a file containing cookies, possibly for information gathering
  • Harvests credentials from local FTP client softwares
  • Installs WinPCAP
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Lazy.331927?


File Info:

name: 8A37AAD191BEAEC60295.mlw
path: /opt/CAPEv2/storage/binaries/203c659460a9387bfccdb8784ffc5c2b06759961eef109f7b972baf335174e22
crc32: B1EF14B7
md5: 8a37aad191beaec602952c33bbf41f30
sha1: f46b73866632fc58aa45beece2e201db03edfa66
sha256: 203c659460a9387bfccdb8784ffc5c2b06759961eef109f7b972baf335174e22
sha512: 57cfea85192e92062e131f485ef446216695c9fbd6a4632abda9b8bba0a4e207b880ec60b9128edf10053fcb11af8480a8088909372c571d30cc7df3133f5bf4
ssdeep: 12288:pmNFxw8+e53POk7/B/Msv9l2M6/AIo5N3ESugRXG5Px2BOtww:pmNFx0e5mkjRMjwLW5Mwt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14D052383DAC11874CEA4B63184F0AE88F21B0C5585549DB67E2CACE3277F7025B5A6F7
sha3_384: b82afaca0256193bebdc8ab66f9eb5ea15975a604ec9acf11337e9f6f6e0fea5392227a72381b107b11dc3b61b172c0d
ep_bytes: 33c009e0663df0fd72678d15b09fbfff
timestamp: 2014-02-01 17:22:31

Version Info:

0: [No Data]

Lazy.331927 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lKKk
tehtrisGeneric.Malware
CynetMalicious (score: 100)
FireEyeGeneric.mg.8a37aad191beaec6
McAfeeGeneric-FAOM!8A37AAD191BE
Cylanceunsafe
ZillyaTrojan.Kryptik.Win32.760227
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005485311 )
AlibabaMalware:Win32/km_28f37.None
K7GWTrojan ( 005485311 )
Cybereasonmalicious.191bea
CyrenW32/S-3748bbd6!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.BUEX
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Lazy.331927
NANO-AntivirusTrojan.Win32.Stealer.dwpfgl
SUPERAntiSpywareTrojan.Agent/Gen-Blocker
MicroWorld-eScanGen:Variant.Lazy.331927
AvastWin32:Evo-gen [Trj]
TencentWin32.Trojan.Generic.Ctgl
SophosMal/FakeAV-UF
F-SecureTrojan.TR/Crypt.XPACK.Gen7
DrWebTrojan.PWS.Stealer.10971
VIPREGen:Variant.Lazy.331927
TrendMicroTROJ_KRYPTK.SM99
McAfee-GW-EditionBehavesLike.Win32.Backdoor.cc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Lazy.331927 (B)
IkarusTrojan.Crypt
GDataGen:Variant.Lazy.331927
JiangminTrojan/Generic.bchnj
WebrootW32.Kryptik
AviraTR/Crypt.XPACK.Gen7
Antiy-AVLTrojan[Backdoor]/Win32.Hlux
XcitiumTrojWare.Win32.Kryptik.BLUQ@57vc6c
ArcabitTrojan.Lazy.D51097
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftVirTool:Win32/Obfuscator
GoogleDetected
AhnLab-V3Trojan/Win32.Kryptk.R98521
BitDefenderThetaGen:NN.ZexaF.36662.0mX@aaTO5Cp
ALYacGen:Variant.Lazy.331927
MAXmalware (ai score=100)
VBA32Heur.Trojan.Hlux
MalwarebytesMalware.Heuristic.1006
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_KRYPTK.SM99
RisingRogue.Winwebsec!8.B21 (TFE:1:I9rtrjjik7E)
YandexBackdoor.Hlux!thfAYKSlc1U
SentinelOneStatic AI – Suspicious PE
FortinetW32/Generic.AC.BFFEB!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Lazy.331927?

Lazy.331927 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment