Malware

About “Lazy.342961” infection

Malware Removal

The Lazy.342961 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.342961 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Lazy.342961?


File Info:

name: FAEAA9CFEA10517CF163.mlw
path: /opt/CAPEv2/storage/binaries/de0fa8e488e9e4495f650c7c39e6950c6add14188648da19ff95f3165eba5de6
crc32: 1561B0BD
md5: faeaa9cfea10517cf1632a40f01fb724
sha1: 52bca7d2d0413a526ad19f62f57da504e4b78fe4
sha256: de0fa8e488e9e4495f650c7c39e6950c6add14188648da19ff95f3165eba5de6
sha512: 4ddc17c1e4a91ac9cdbd860bc50d34cdc7d9a8646e4392737d2f3e8e0b48e913506e077b4182f4dad60864616f18040929026933cde3927cd2cd6ae886a81863
ssdeep: 12288:cqOU/42Drd48NO1m0c5n0ojVDa/ZSG2i:cqj42D5REm0anTa/ZSG2i
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T141154ACC62511083E0496E7B692D8A6DDD023BFC6A23FF223047BB5A796C7F19D06674
sha3_384: 3bfdf430f52545d8ef460580d5c79e14ce5097e7486eadf2242f3d18df9dee4f41594c1b02ac512e10630f0178b8f974
ep_bytes: 397210fb691b947c6cfa9dedeeb0f557
timestamp: 1972-09-27 00:00:00

Version Info:

0: [No Data]

Lazy.342961 also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Lazy.342961
ClamAVWin.Packed.Dridex-9860931-1
FireEyeGeneric.mg.faeaa9cfea10517c
McAfeePacked-FJB!FAEAA9CFEA10
MalwarebytesCrypt.Trojan.Malicious.DDS
VIPREGen:Variant.Lazy.342961
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
K7GWTrojan ( 005a14d51 )
Cybereasonmalicious.fea105
CyrenW32/Copak.E.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik_AGen.BFL
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Trojan.Win32.Copak.gen
BitDefenderGen:Variant.Lazy.342961
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Kryptik.gifya
EmsisoftGen:Variant.Lazy.342961 (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebTrojan.PackedENT.216
McAfee-GW-EditionBehavesLike.Win32.Corrupt.dm
Trapminemalicious.moderate.ml.score
SophosMal/Inject-GJ
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.707O5V
JiangminTrojan.Selfmod.aomx
AviraTR/Crypt.ZPACK.Gen
MAXmalware (ai score=88)
Antiy-AVLTrojan/Win32.Kryptik.GIFY
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
ArcabitTrojan.Lazy.D53BB1
ZoneAlarmVHO:Trojan.Win32.Copak.gen
MicrosoftTrojan:Win32/Glupteba.MT!MTB
GoogleDetected
AhnLab-V3Trojan/Win.OB.C5394211
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36196.48X@a81Hwbc
ALYacGen:Variant.Lazy.342961
TACHYONTrojan/W32.Selfmod
VBA32Trojan.Copak
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.BF57 (CLASSIC)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Lazy.342961?

Lazy.342961 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment