Malware

How to remove “Lazy.412303”?

Malware Removal

The Lazy.412303 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.412303 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Lazy.412303?


File Info:

name: 8FB2F593272F5951097C.mlw
path: /opt/CAPEv2/storage/binaries/07adceb0e14d29fb1c720bb16f8558a53e1143da87983f7889fc8bc7c8e48df4
crc32: A3B2FDE5
md5: 8fb2f593272f5951097c14f1798dfca1
sha1: 8aa3a425d221c63537b1411c0009f7f1f2dde949
sha256: 07adceb0e14d29fb1c720bb16f8558a53e1143da87983f7889fc8bc7c8e48df4
sha512: e8b44a4e4e36fcdd6e00ca8cacecc5f13117b72da8b6e3bba4626b12d9fce46fd121fbb85869ee66b59537cabf429f34a2478419ae1a2d5a7c540002871cf59d
ssdeep: 49152:jtPKFsnxzckaneswPklkqRRtpjKqmbqwBOnmDER6HCSN4YeiaO0a99:jtnYkcRZKqRTKqJYimDY6zuYrMg9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T164C5237131C1C475E9671431AEA4DB74AAA0FD397992814A7BE03F2FB9308D6CB16B13
sha3_384: bce274f545fdb6da1e017234429a27d835b6a20da0f820ecb5dc1bd7be7317e09d21841939ba27e30f14fa96f8e36c39
ep_bytes: e8df650000e978feffff8bff558bec56
timestamp: 2016-02-03 19:38:25

Version Info:

0: [No Data]

Lazy.412303 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Lazy.412303
ALYacGen:Variant.Lazy.412303
Cylanceunsafe
K7GWTrojan ( 005a546d1 )
K7AntiVirusTrojan ( 005a546d1 )
ArcabitTrojan.Lazy.D64A8F
BaiduWin32.Trojan.FlyStudio.lh
tehtrisGeneric.Malware
AvastWin32:MalwareX-gen [Trj]
BitDefenderGen:Variant.Lazy.412303
RisingTrojan.Generic@AI.97 (RDML:RkWx95UisUEEXiZTQ9W0bg)
EmsisoftGen:Variant.Lazy.412303 (B)
VIPREGen:Variant.Lazy.412303
Trapminesuspicious.low.ml.score
FireEyeGen:Variant.Lazy.412303
SophosMal/Generic-S
IkarusTrojan.Win32.VMProtect
VaristW32/ABRisk.ESOE-0734
MAXmalware (ai score=81)
Antiy-AVLGrayWare/Win32.Wacapew
MicrosoftPUA:Win32/Vigua.A
GDataGen:Variant.Lazy.412303
GoogleDetected
McAfeeArtemis!CDD7B80A346A
TrendMicro-HouseCallTROJ_GEN.R002H09JI23
SentinelOneStatic AI – Malicious SFX
FortinetPossibleThreat.ZDS
BitDefenderThetaGen:NN.ZemsilF.36804.Zw3@aKsEPQm
AVGWin32:MalwareX-gen [Trj]

How to remove Lazy.412303?

Lazy.412303 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment