Malware

How to remove “Lazy.361740”?

Malware Removal

The Lazy.361740 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.361740 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Lazy.361740?


File Info:

name: E7AFA275294EC6FDE5C5.mlw
path: /opt/CAPEv2/storage/binaries/bf200467324488ee88720ff8cddea1b6b71d84211f0cef231cee6ea49962f443
crc32: C38D1A07
md5: e7afa275294ec6fde5c5221a94f14d04
sha1: 221d5a5e4e6e6ae1002f03d4d90bb6df2f863cf3
sha256: bf200467324488ee88720ff8cddea1b6b71d84211f0cef231cee6ea49962f443
sha512: a5bc007ba84ecfbc757bcd891c2204cf901df777253f7168b229533803e6a4f75770749dd30e2473bdd2ddb122610409f00e4bbc40d7abb9ae440919e1507cbf
ssdeep: 6144:2b8h8/l/iEM/NgDGLlRHEOkHZQd3Jv3iiirxMpAZA3mTpPpXGCTqswABrxxJa/YB:2bxD5idAPTDGaJjlDa/ZS7W+iniF+G4Q
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1F4256A4D17761653C50507BF297DCA2091CE68F832AEC6A23C40B95BF6637D78AB3938
sha3_384: f7413a0ccf4c12122b62af549224e1327b2f150470ec1983684edd8d60d131a9156e1639733f253139638b8e9339190d
ep_bytes: 6c05960e3c6c1289398d1b18bbc773a2
timestamp: 1971-05-16 00:00:00

Version Info:

0: [No Data]

Lazy.361740 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.361740
SkyhighBehavesLike.Win32.Picsys.th
McAfeeTrojan-FVOQ!E7AFA275294E
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Lazy.361740
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
K7GWTrojan ( 005a45ef1 )
Cybereasonmalicious.e4e6e6
ArcabitTrojan.Lazy.D5850C
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik_AGen.BFL
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Dridex-9860931-1
KasperskyVHO:Trojan.Win32.Copak.gen
BitDefenderGen:Variant.Lazy.361740
NANO-AntivirusTrojan.Win32.Selfmod.icgfyy
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Selfmod.ka
EmsisoftGen:Variant.Lazy.361740 (B)
F-SecureTrojan.TR/Dropper.Gen
ZillyaTrojan.Kryptik.Win32.3180870
SophosMal/Inject-GJ
IkarusTrojan.Win32.Glupteba
VaristW32/Ulise.FE.gen!Eldorado
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.Kryptik.gify
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
MicrosoftTrojan:Win32/Glupteba.MT!MTB
ZoneAlarmVHO:Trojan.Win32.Copak.gen
GDataWin32.Trojan.PSE.15NLAT
GoogleDetected
AhnLab-V3Trojan/Win.OB.C5394211
Acronissuspicious
VBA32Trojan.Copak
ALYacGen:Variant.Lazy.361740
TACHYONTrojan/W32.Selfmod
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.BF57 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GIFQ!tr
BitDefenderThetaGen:NN.ZexaF.36680.a9Z@aawZ@hf
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Lazy.361740?

Lazy.361740 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment