Malware

How to remove “Lazy.357829 (B)”?

Malware Removal

The Lazy.357829 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.357829 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Lazy.357829 (B)?


File Info:

name: 1DD2C4E1FD67A33FA29F.mlw
path: /opt/CAPEv2/storage/binaries/921b106b6fe0f28efc2ca8cdbfecfd7e2dd7991ca78a9d93562c6a0d1a273daa
crc32: 64F33B50
md5: 1dd2c4e1fd67a33fa29fd9f429cb362f
sha1: 490e1eb951efda41439701c3dba7067459854d57
sha256: 921b106b6fe0f28efc2ca8cdbfecfd7e2dd7991ca78a9d93562c6a0d1a273daa
sha512: cfe6197595416d4b0467553f2b0951ae24a673d21a5120166dd23f2da12e74fea5e4edb6c208db69172eff4bad29568f3bab16664e6fe8a6e3d528074d2274f8
ssdeep: 6144:x5N4iSAEmi4AZGBxR3XpYv5lOGhsldsQdQZ:thEmMAyQdQZ
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T117448D127DA14AE2E2251832BCAC99134D39F4E04E755A8B3F3CA6144EB11F5B9F0DDE
sha3_384: 4e2767eb7b899356e281ad123b7cfdbaab67a24e9993b2c8f5efaf6cbdad0ef6f93e9bd99cec437fef4a3ce5225df509
ep_bytes: e8e2020000e974feffff558bec83ec0c
timestamp: 1970-01-01 00:00:00

Version Info:

Comments: This is a legitimate application.
CompanyName: Uganda National Oil Company
FileDescription: Uganda National Oil Company Product
FileVersion: 846
InternalName: EYILJmRZ8Ubw
LegalCopyright: © Uganda National Oil Company All rights reserved.
LegalTrademarks: © Uganda National Oil Company Trademarks
OriginalFilename: aVg7g2Sc.exe
ProductName: QTEANZjp7p
ProductVersion: 846
Translation: 0x0407 0x04b0

Lazy.357829 (B) also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.Y!c
MicroWorld-eScanGen:Variant.Lazy.357829
FireEyeGeneric.mg.1dd2c4e1fd67a33f
CAT-QuickHealTrojan.GenericPMF.S30358666
McAfeeRDN/Generic BackDoor
Cylanceunsafe
ZillyaTrojan.Stealer.Win32.122006
SangforInfostealer.Win32.Kryptik.Vits
K7AntiVirusTrojan ( 005a79e41 )
AlibabaTrojan:Win32/GenKryptik.3dbcf518
K7GWTrojan ( 005a79e41 )
ArcabitTrojan.Lazy.D575C5
VirITTrojan.Win32.GenusT.DNXF
CyrenW32/Kryptik.KCI.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HTYZ
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
BitDefenderGen:Variant.Lazy.357829
NANO-AntivirusTrojan.Win32.Stealer.jxplnj
AvastWin32:PWSX-gen [Trj]
TencentMalware.Win32.Gencirc.10bf0269
SophosTroj/Krypt-AAT
F-SecureTrojan.TR/AD.RedLineSteal.qcjcw
DrWebTrojan.PWS.RedLineNET.7
VIPREGen:Variant.Lazy.357829
TrendMicroTrojanSpy.Win32.REDLINE.YXDGCZ
McAfee-GW-EditionRDN/Generic BackDoor
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Lazy.357829 (B)
IkarusTrojan.Win32.Redline
AviraTR/AD.RedLineSteal.qcjcw
Antiy-AVLTrojan/Win32.Kryptik
MicrosoftTrojan:Win32/Amadey.AD!MTB
ZoneAlarmHEUR:Trojan-Spy.Win32.Stealer.gen
GDataWin32.Trojan.PSE.1ENI62
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R589620
BitDefenderThetaGen:NN.ZexaF.36348.pq2@aCf72Lji
ALYacGen:Variant.Lazy.357829
MAXmalware (ai score=82)
VBA32BScope.Backdoor.Agent
MalwarebytesTrojan.Crypt
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojanSpy.Win32.REDLINE.YXDGCZ
RisingTrojan.Kryptik!1.E841 (CLASSIC)
YandexTrojan.Kryptik!Xe6oNBZbasg
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.W32.Injurer.gen
FortinetW32/GenKryptik.GLIH!tr
AVGWin32:PWSX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Lazy.357829 (B)?

Lazy.357829 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment