Malware

Lazy.340617 removal

Malware Removal

The Lazy.340617 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.340617 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Lazy.340617?


File Info:

name: 111BEBE6CCF405E0A6D9.mlw
path: /opt/CAPEv2/storage/binaries/6d63aa7416687764636329b6e59801fcbd883b1b70a276276380e28492ef86ec
crc32: 3215E041
md5: 111bebe6ccf405e0a6d9e5b233441fc0
sha1: ea4ab9f93ec5041ea1d0ec645b9db38529e9a5fb
sha256: 6d63aa7416687764636329b6e59801fcbd883b1b70a276276380e28492ef86ec
sha512: 5532d650db1755506f54719fecbe22d1f6abd43a37f74f2fb8bd3e009efcc513cfb9517e02d11e942dd6fcdac08e1f8db26449f78648bb03f915de3fa427bae2
ssdeep: 24576:92fCRL4D68uN52BUPmuSHDpjKJRl1Bbm8rW:96xB+HSjpjK3LB
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1531549D6BA3C897BCC6735B64B9E4F906792DC192281C8BD33F1960E57B9640B98D30C
sha3_384: dd5a0a823b2b5e6b0bbde781fdd2af27bc649936060c5bd1baec05e63a053d808c43a330d09a42c0113ad56f13154e0f
ep_bytes: 5589e5c60540734400016820ea4c006a
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Lazy.340617 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.MulDrop22.5
MicroWorld-eScanGen:Variant.Lazy.340617
FireEyeGeneric.mg.111bebe6ccf405e0
ALYacGen:Variant.Lazy.340617
ZillyaDropper.Dorifel.Win32.67185
CrowdStrikewin/malicious_confidence_60% (D)
BitDefenderGen:Variant.Lazy.340617
ArcabitTrojan.Lazy.D53289
BitDefenderThetaGen:NN.ZexaF.36196.2CX@ai6t!fh
CyrenW32/Delf.VR.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Delf.UYZ
CynetMalicious (score: 100)
KasperskyUDS:Trojan.Win32.Agent
NANO-AntivirusTrojan.Win32.Redcap.jvytnu
RisingTrojan.Delf!8.67 (TFE:5:a5TEcWQEVkI)
F-SecureTrojan.TR/Redcap.vzkuq
VIPREGen:Variant.Lazy.340617
McAfee-GW-EditionBehavesLike.Win32.Infected.ch
EmsisoftGen:Variant.Lazy.340617 (B)
JiangminTrojanDropper.Dorifel.bast
AviraTR/Redcap.vzkuq
MAXmalware (ai score=89)
Antiy-AVLTrojan[Dropper]/Win32.Dorifel
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ZoneAlarmUDS:Trojan.Win32.Agent
GDataGen:Variant.Lazy.340617
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R576340
McAfeeGenericRXVW-VR!111BEBE6CCF4
DeepInstinctMALICIOUS
VBA32BScope.TrojanDropper.Dorifel
MalwarebytesMalware.AI.2180420744
PandaTrj/Genetic.gen
TencentMalware.Win32.Gencirc.10beac59
YandexTrojan.Delf!yXzToywYvAg
IkarusTrojan.Win32.Delf
MaxSecureTrojan.Malware.207234223.susgen
FortinetW32/Delf.UYZ!tr
AVGWin32:DropperX-gen [Drp]
AvastWin32:DropperX-gen [Drp]

How to remove Lazy.340617?

Lazy.340617 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment