Malware

Lazy.357829 removal guide

Malware Removal

The Lazy.357829 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.357829 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Lazy.357829?


File Info:

name: BA469586E1C1B6A6AA23.mlw
path: /opt/CAPEv2/storage/binaries/2f2a928a1f958b8d716c089cd229ad1ced96a9a79eab98bf2e85ebb1c3a00fc6
crc32: AC1216ED
md5: ba469586e1c1b6a6aa23fab60e05e956
sha1: eb6e3c6958b9699faafc774e8ae2f0ed1e9f01f8
sha256: 2f2a928a1f958b8d716c089cd229ad1ced96a9a79eab98bf2e85ebb1c3a00fc6
sha512: 6f33a5ce493e25c873bbdd45efd69b0c9e9a94cc54b64a37faf459e59402918ea55d0f8e4d68ddfd2dface9b551103635da11c0e3e4525d6b668d4e15f715135
ssdeep: 3072:z5U/XwnbtpYmJHINEL5+u6Su1YjQHPCGikQ7rP3SQSD1YHnOGTqpOMa2chgkZask:z5U/XEn8vCybgnOHgfasFt7VULQdQZ
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1BD54284134A07851D51F68366C9C907D8A38A8F20B358B8E3EAD1B17CA737F069F5F69
sha3_384: 6c9bd31cfe7bdd28f51c613422b7dcc4ae193391ed3a36670dc0d46165687ed39b0dec9aa7edb81eae1986a390795cd6
ep_bytes: e8e2020000e974feffff558bec83ec0c
timestamp: 1970-01-01 00:00:00

Version Info:

Comments: This is a legitimate application.
CompanyName: Uganda National Oil Company
FileDescription: Uganda National Oil Company Product
FileVersion: 846
InternalName: EYILJmRZ8Ubw
LegalCopyright: © Uganda National Oil Company All rights reserved.
LegalTrademarks: © Uganda National Oil Company Trademarks
OriginalFilename: aVg7g2Sc.exe
ProductName: QTEANZjp7p
ProductVersion: 846
Translation: 0x0407 0x04b0

Lazy.357829 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Stealer.12!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.RedLineNET.7
MicroWorld-eScanGen:Variant.Lazy.357829
ClamAVWin.Trojan.Pwsx-10005423-0
FireEyeGeneric.mg.ba469586e1c1b6a6
CAT-QuickHealTrojan.GenericPMF.S30358666
McAfeeGenericRXWF-LK!BA469586E1C1
MalwarebytesTrojan.Crypt
ZillyaTrojan.Stealer.Win32.124733
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005a79cc1 )
AlibabaTrojan:Win32/Kryptik.44fd37ac
K7GWTrojan ( 005a79e41 )
BitDefenderThetaGen:NN.ZexaF.36348.sq2@amKlOGdi
VirITTrojan.Win32.GenusT.DNTP
CyrenW32/Kryptik.KCI.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HTYZ
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:Trojan-Spy.Win32.Stealer
BitDefenderGen:Variant.Lazy.357829
NANO-AntivirusTrojan.Win32.RedLineNET.jxbzfr
AvastWin32:PWSX-gen [Trj]
TencentMalware.Win32.Gencirc.10bf01db
EmsisoftGen:Variant.Lazy.357829 (B)
F-SecureTrojan.TR/AD.RedLineSteal.egjaj
VIPREGen:Variant.Lazy.357829
TrendMicroTrojanSpy.Win32.REDLINE.YXDGAZ
McAfee-GW-EditionGenericRXWF-LK!BA469586E1C1
Trapminemalicious.high.ml.score
SophosTroj/Krypt-AAT
IkarusTrojan.Win32.Redline
GDataWin32.Trojan.PSE.1ENI62
AviraTR/AD.RedLineSteal.egjaj
MAXmalware (ai score=86)
Antiy-AVLTrojan/Win32.GenKryptik
ArcabitTrojan.Lazy.D575C5
ZoneAlarmUDS:Trojan-Spy.Win32.Stealer
MicrosoftTrojan:Win32/Amadey.AD!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R589378
VBA32TrojanSpy.Stealer
ALYacGen:Variant.Lazy.357829
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojanSpy.Win32.REDLINE.YXDGAZ
RisingTrojan.Kryptik!1.E841 (CLASSIC)
YandexTrojan.GenKryptik!Xf74dzmdTC0
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.W32.Injurer.gen
FortinetW32/GenKryptik.GLIH!tr
AVGWin32:PWSX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Lazy.357829?

Lazy.357829 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment