Malware

What is “Lazy.379834”?

Malware Removal

The Lazy.379834 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.379834 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Attempts to create or modify system certificates
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Lazy.379834?


File Info:

name: 67EFD09C85925DD4CE3C.mlw
path: /opt/CAPEv2/storage/binaries/5691867ad3aee45e3737888b1dd171962e96cec75c96befad4b9b2f9ffe83ab6
crc32: 3CE3EC0A
md5: 67efd09c85925dd4ce3cc8031434cf70
sha1: 16de922120790a9599bf698ee96cb4b24a3670b4
sha256: 5691867ad3aee45e3737888b1dd171962e96cec75c96befad4b9b2f9ffe83ab6
sha512: 148d25af8450916110408b7f7f4063a7110a3cc8a03c7c0046c776e5d30f3e729cd10d875184b3dbfb191560628403fa7c0696cc9bd4ce7bc7e6b30a84ea1758
ssdeep: 12288:TOmR8JC30f3nh6u/U6VKZiEWFNRQuan/66Nn3:TjR0Cq3h6u/U6AYNYnX3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A1C49D16FAA150F5D06791B99172072FFE747C061B604AEB57E08E243EB3BE05A6FB40
sha3_384: 7173704af33916012ccdad1b2523ca6cc00bb6deee3f1ff908b6c8bd546efc0ff46ed43582852ab63e64263ed41bd0cb
ep_bytes: 558bec6aff68d001420068c86f410064
timestamp: 2023-08-24 01:18:05

Version Info:

FileVersion: 1.0.0.0
FileDescription: 易语言程序
ProductName: 易语言程序
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Lazy.379834 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.379834
ClamAVWin.Dropper.Tiggre-9845940-0
FireEyeGeneric.mg.67efd09c85925dd4
CAT-QuickHealRisktool.Flystudio.17324
ALYacGen:Variant.Lazy.379834
MalwarebytesPUP.Optional.ChinAd
SangforTrojan.Win32.Save.BlackMoon
Cybereasonmalicious.120790
CyrenW32/ABRisk.SHHY-4847
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.BlackMoon.A suspicious
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:Trojan.Win32.GenericML.xnet
BitDefenderGen:Variant.Lazy.379834
AvastWin32:MalwareX-gen [Trj]
EmsisoftApplication.Generic (A)
F-SecureHeuristic.HEUR/AGEN.1356148
VIPREGen:Variant.Lazy.379834
McAfee-GW-EditionBehavesLike.Win32.RealProtect.hh
Trapminemalicious.high.ml.score
SophosBlackMoon Packed (PUA)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.Agent.WP
AviraHEUR/AGEN.1356148
Antiy-AVLTrojan/Win32.Blamon.a
ZoneAlarmUDS:Trojan.Win32.GenericML.xnet
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
Acronissuspicious
McAfeeArtemis!67EFD09C8592
MAXmalware (ai score=84)
VBA32BScope.Trojan.Wacatac
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H0CHO23
RisingTrojan.Generic@AI.99 (RDML:H3Sh2w0KeaUwM29GGZRobw)
IkarusAdWare.Win32.BlackMoon
MaxSecureDropper.Dinwod.frindll
FortinetW32/CoinMiner.WP!tr
BitDefenderThetaGen:NN.ZexaF.36350.Hq0@aO!MWYbb
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Lazy.379834?

Lazy.379834 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment