Malware

How to remove “Lazy.355849”?

Malware Removal

The Lazy.355849 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.355849 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Lazy.355849?


File Info:

name: A9F4DCE38E4E88350D3A.mlw
path: /opt/CAPEv2/storage/binaries/40c4c1a8814b4b21e37d2d2b578b47b0c12f098170f1abd56761fdddf1611e33
crc32: 9DCF988B
md5: a9f4dce38e4e88350d3a223d42c28510
sha1: 0d49fd92217f81ac0cf799e2bb81c7da8ce4d796
sha256: 40c4c1a8814b4b21e37d2d2b578b47b0c12f098170f1abd56761fdddf1611e33
sha512: af5e501aa08f67199125b5304c386c56906a62ac172e95a95a441384b1ae4eba2a52c78f01327a0aab10b14248ad76b167235e7e1664d9ed18637e0fafd4f1d9
ssdeep: 24576:lMD/FKGpuxasP8rgb7OkNu74BK6RsP8fvZDjMF3W5SodFrmY:ytexasE0Bu736RskfvZDjMFm5Rv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T131D53A3A14AC23B6C0F56DF243B2DC62BD8EB4FB9A4C041675F9164BFE4925066D122F
sha3_384: 5b20b6dcd4ec0d44e74635905167ecba77cd1deb06fd021164d3f81792a762262cfedd0ce981ff318c7887e004e6fa29
ep_bytes: 558bec83ec4064a1300000005356578b
timestamp: 2017-06-26 02:33:10

Version Info:

0: [No Data]

Lazy.355849 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Injuke.16!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.355849
SkyhighBehavesLike.Win32.RealProtect.vm
ALYacGen:Variant.Lazy.355849
MalwarebytesMalware.AI.726544542
VIPREGen:Variant.Lazy.355849
SangforRiskware.Win32.Cymulate.Vp9t
K7AntiVirusRiskware ( 00569ce81 )
BitDefenderGen:Variant.Lazy.355849
K7GWRiskware ( 00569ce81 )
Cybereasonmalicious.2217f8
BitDefenderThetaGen:NN.ZexaF.36792.OEW@aOI64of
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/RiskWare.Cymulate.A
APEXMalicious
KasperskyHEUR:Trojan.Win32.Injuke.pef
AlibabaTrojan:MSIL/Cymulate.57f32187
NANO-AntivirusExploit.Win32.CVE20188440.jwxbgt
RisingHackTool.Cymulate!8.137FC (TFE:4:WoqaLq1VfzC)
SophosMal/Generic-S
ZillyaTool.Cymulate.Win32.7711
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.a9f4dce38e4e8835
EmsisoftGen:Variant.Lazy.355849 (B)
IkarusPUA.RiskWare.Cymulate
GoogleDetected
VaristW32/ABRisk.DKEI-3449
Antiy-AVLRiskWare/Win32.Cymulate
Kingsoftmalware.kb.a.984
MicrosoftHackTool:Win32/Cymulion
ArcabitTrojan.Lazy.D56E09
ZoneAlarmHEUR:Trojan.Win32.Injuke.pef
GDataGen:Variant.Lazy.355849
CynetMalicious (score: 100)
McAfeeArtemis!A9F4DCE38E4E
MAXmalware (ai score=86)
DeepInstinctMALICIOUS
VBA32Trojan.Injuke
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H07JA23
TencentWin32.Trojan.Injuke.Umhl
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.121169836.susgen
FortinetRiskware/Cymulate
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Lazy.355849?

Lazy.355849 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment