Malware

Lazy.428911 removal guide

Malware Removal

The Lazy.428911 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.428911 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Lazy.428911?


File Info:

name: 6BEB929571B668600CB0.mlw
path: /opt/CAPEv2/storage/binaries/23ef2c336aacb708024772da37172053a92f76f85a85a4bc9fdc15f043a86856
crc32: 521CFB32
md5: 6beb929571b668600cb0c798e884f7f2
sha1: 0477ea42176b9e01b05e64ad3774b70bea5859c4
sha256: 23ef2c336aacb708024772da37172053a92f76f85a85a4bc9fdc15f043a86856
sha512: afd4dc8da120ba5f369602c75153a27259468917f261332b37384547d84065d19ea04dad988919d539ae4e932e82308ef48d6746e81042690bf2bfe3f06120ca
ssdeep: 12288:hqal8j46Q/dAVe91W1BUAn1Mo75VhZ2Q:83j4z/dAVe9YymVhZ2Q
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T181B4AEAC760A4FA0EBE82330CC0E219E5A162721DDAF430CCB7179781D6E9DDE66D517
sha3_384: b64dd038a8d761a1549d345909c5c1ddd410e004f1736441c4501223efaba9f4b1fe7ea38b73812fb8fc802b97a96a43
ep_bytes: 2c0ff95d7c667dda7987744b6bc51cf1
timestamp: 1971-05-16 00:00:00

Version Info:

0: [No Data]

Lazy.428911 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.428911
ClamAVWin.Packed.Dridex-9775371-1
FireEyeGeneric.mg.6beb929571b66860
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Generic.Win32.466665
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
K7GWTrojan ( 005a45ef1 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Lazy.D68B6F
BitDefenderThetaGen:NN.ZexaF.36744.GWZ@aSxTrqd
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik_AGen.BFL
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Trojan.Win32.Copak.gen
BitDefenderGen:Variant.Lazy.428911
NANO-AntivirusTrojan.Win32.Copak.jwlpkm
AvastWin32:TrojanX-gen [Trj]
RisingTrojan.Kryptik!1.B34D (CLASSIC)
TACHYONTrojan/W32.Selfmod
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.PackedENT.123
VIPREGen:Variant.Lazy.428911
SophosTroj/Agent-BFEY
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.cwjtj
VaristW32/Trojan.NJGF-3047
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.Kryptik.girh
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
ZoneAlarmVHO:Trojan.Win32.Copak.gen
GDataWin32.Trojan.PSE.11XGYE9
AhnLab-V3Packed/Win.FJB.C5537157
Acronissuspicious
ALYacGen:Variant.Lazy.428911
MAXmalware (ai score=84)
VBA32Trojan.Khalesi
Cylanceunsafe
PandaTrj/Genetic.gen
TencentTrojan.Win32.Copak.hm
IkarusTrojan-Downloader.Win32.FakeAlert
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.2176b9
DeepInstinctMALICIOUS

How to remove Lazy.428911?

Lazy.428911 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment