Malware

Lazy.373663 removal guide

Malware Removal

The Lazy.373663 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.373663 virus can do?

  • Unconventionial binary language: Romanian
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Lazy.373663?


File Info:

name: C10E37AB04B8B34DB4AF.mlw
path: /opt/CAPEv2/storage/binaries/f38e6aa2a2de0b5fdfdf62d78039db4799b3140bd60f2f191501c2c6f702266a
crc32: 07FF69AE
md5: c10e37ab04b8b34db4afd557df4014fc
sha1: 46b5a73da4f1f61b7cead100ffe61955f143b684
sha256: f38e6aa2a2de0b5fdfdf62d78039db4799b3140bd60f2f191501c2c6f702266a
sha512: f178bee0949f72b84965d2a38909412900288dcdcea6d3c5a3a31a3db723fdfa56b83e92e07f5c5ef9850292c39908467370b6edbc95bd5151e2ff4751107ca9
ssdeep: 24576:GbCE02GdLz/4qYM3cAYuqtdDDSaOm4MAmKtkfNK154fF+dwnHbCr8bq4rFj/y7TW:EQ2GdLz/4qYM3cJuqtdDDSaOm4MAmKtc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1ED358D32F961B072E4610030734ED7E219BB7134279798A7EFC05A9E667B9C1A234F67
sha3_384: e6fda590b8a65ca613fcda021efa3785a4f2d4dea5f0484ffe4af0c3bedbebf39c77eabe98ecfb39779b3a5776823015
ep_bytes: e89b060000e97afeffff3b0d68305100
timestamp: 2023-08-10 11:56:35

Version Info:

CompanyName: Microsoft
FileDescription: Microsoft Office Installer
FileVersion: 1.0.0.1
InternalName: Office.exe
LegalCopyright: Copyright (C) 2022
OriginalFilename: Office.exe
ProductName: Office
ProductVersion: 1.0.0.1
Translation: 0x0418 0x04b0

Lazy.373663 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.RisePro.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.373663
FireEyeGeneric.mg.c10e37ab04b8b34d
CAT-QuickHealTrojanpws.Risepro
ALYacGen:Variant.Lazy.373663
Cylanceunsafe
ZillyaTrojan.Agent.Win32.3657482
SangforInfostealer.Win32.Risepro.Vzum
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanPSW:Win32/RisePro.abf42ef4
BitDefenderThetaGen:NN.ZexaF.36662.gv0@aGFQtGnk
CyrenW32/ABRisk.LWVH-8324
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.ADVG
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-PSW.Win32.RisePro.gen
BitDefenderGen:Variant.Lazy.373663
AvastWin32:TrojanX-gen [Trj]
TencentMalware.Win32.Gencirc.13ed01e2
EmsisoftGen:Variant.Lazy.373663 (B)
F-SecureTrojan.TR/Agent.rdjdh
DrWebTrojan.PWS.Siggen3.32956
VIPREGen:Variant.Lazy.373663
TrendMicroTROJ_GEN.R002C0XHO23
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
GDataGen:Variant.Lazy.373663
AviraTR/Agent.rdjdh
Antiy-AVLTrojan/Win32.Wacatac
ArcabitTrojan.Lazy.D5B39F
ZoneAlarmHEUR:Trojan-PSW.Win32.RisePro.gen
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R602216
VBA32BScope.Trojan.Agent
MAXmalware (ai score=87)
MalwarebytesSpyware.PasswordStealer
TrendMicro-HouseCallTROJ_GEN.R002C0XHO23
RisingTrojan.Generic@AI.100 (RDML:5MFySsHU59tpBsfTDNMa+g)
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.196579936.susgen
FortinetW32/Agent.ADVG!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Lazy.373663?

Lazy.373663 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment