Malware

Lazy.361740 malicious file

Malware Removal

The Lazy.361740 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.361740 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Lazy.361740?


File Info:

name: A1F5FD7C184E3BBC3CDD.mlw
path: /opt/CAPEv2/storage/binaries/fcf707bc8028f71f99ce8c6b65fed36a149f3901c3508582f1efefb766d867e3
crc32: 1B86190F
md5: a1f5fd7c184e3bbc3cdd72db0c5caef6
sha1: 2a6d2326cd9e080179dcda715188fdc6f4b4669f
sha256: fcf707bc8028f71f99ce8c6b65fed36a149f3901c3508582f1efefb766d867e3
sha512: 590e45baeb07423fba1e5e485b418428e1bf45b133b8246cf287197f437f280bd830281aa7e74e67725784e714994498ec3eeeb9b9bb8569b76cbf88a30c84c0
ssdeep: 6144:xNOFAh5wspR80oJZeQ0eWEl3pdv9KuHtIwABrxxJa/YES7W+JW:iOznpR80oJn0exlZDKcKjlDa/ZS7W+A
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T16E156B0D33726293C17822BBFE1EDE60B00969387A56E6B230477BDB7961BC4D457839
sha3_384: 996d450be9e0b006105708eb2c0d3ef9bfc41f092282d70f71a055c21bcb0fc488b95c82296b8294481d0f3a6d0b3816
ep_bytes: 63076d48336ee9cf368fe05eb4c588e4
timestamp: 1971-05-16 00:00:00

Version Info:

0: [No Data]

Lazy.361740 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.361740
FireEyeGeneric.mg.a1f5fd7c184e3bbc
SkyhighBehavesLike.Win32.Infected.dm
ALYacGen:Variant.Lazy.361740
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Lazy.361740
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
BitDefenderGen:Variant.Lazy.361740
K7GWTrojan ( 005a14d51 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36792.48W@aawZ@hf
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik_AGen.BFL
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Dridex-9860931-1
KasperskyVHO:Trojan.Win32.Selfmod.gen
RisingTrojan.Kryptik!1.B34D (CLASSIC)
TACHYONTrojan/W32.Selfmod
SophosMal/Inject-GJ
ZillyaTrojan.Kryptik.Win32.4240322
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Lazy.361740 (B)
IkarusTrojan.Win32.Glupteba
VaristW32/Ulise.FE.gen!Eldorado
Antiy-AVLTrojan/Win32.Kryptik.GIFY
Kingsoftmalware.kb.a.984
MicrosoftTrojan:Win32/Glupteba.MT!MTB
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
ArcabitTrojan.Lazy.D5850C
ZoneAlarmVHO:Trojan.Win32.Selfmod.gen
GDataWin32.Trojan.PSE.1B28NHU
GoogleDetected
AhnLab-V3Trojan/Win.OB.C5394211
Acronissuspicious
McAfeeTrojan-FVOQ!A1F5FD7C184E
MAXmalware (ai score=80)
DeepInstinctMALICIOUS
VBA32Trojan.Copak
Cylanceunsafe
PandaTrj/Genetic.gen
TencentTrojan.Win32.Selfmod.ka
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.6cd9e0
AvastWin32:Evo-gen [Trj]

How to remove Lazy.361740?

Lazy.361740 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment