Malware

Lazy.430963 (file analysis)

Malware Removal

The Lazy.430963 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.430963 virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Lazy.430963?


File Info:

name: 242E7D7961B6091A9EF2.mlw
path: /opt/CAPEv2/storage/binaries/ab1202493d6d4dd7df1f197c8b41c5068006d5cfe90fc2ebdf69b43d52a313f6
crc32: C368BB71
md5: 242e7d7961b6091a9ef20935e27f271c
sha1: 32be8e74720a4c9b3d026735243fb205818269d0
sha256: ab1202493d6d4dd7df1f197c8b41c5068006d5cfe90fc2ebdf69b43d52a313f6
sha512: 0ee8bfc7f20e60dfeff152ea229cbc0891f0487d3e47414fee3670bc3b9ea8a812bec03d792fc02a51714a0a86162a31bd1b1ebf60ab3e7c59a34993666f6164
ssdeep: 12288:ZAC+DyQFBakd9gtfzVQ5zCD4VZRDGWF1m3aYhOA6eXVQ5zCD4V4:ZAC+DLPytfzVQ5zY431CaYAeXVQ5zY42
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1FDF4ADD8FC4F0791CCE7797349B1B141A5C6A27A9EAF4094ECB41079FC35984B23E4AA
sha3_384: 1ff2b1057d3865ca9de5cff6baf4a38a101e8958fbc5459a237e843a4cc1726623a00f5854f040e48f173ab0f1d1a1fd
ep_bytes: de1d1a838e749e048b95979599d7ff2f
timestamp: 1971-05-16 00:00:00

Version Info:

0: [No Data]

Lazy.430963 also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Lazy.430963
ClamAVWin.Packed.Razy-9828382-0
FireEyeGeneric.mg.242e7d7961b6091a
SkyhighBehavesLike.Win32.Glupteba.bc
ALYacGen:Variant.Lazy.430963
MalwarebytesCrypt.Trojan.MSIL.DDS
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
K7GWTrojan ( 005a45ef1 )
Cybereasonmalicious.4720a4
ArcabitTrojan.Lazy.D69373
BitDefenderThetaGen:NN.ZexaF.36792.T8Z@a83RoFe
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik_AGen.BGU
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Trojan.Win32.Copak.gen
BitDefenderGen:Variant.Lazy.430963
NANO-AntivirusTrojan.Win32.PackedDownloader.ijxqni
AvastWin32:TrojanX-gen [Trj]
TACHYONTrojan/W32.Selfmod
SophosTroj/Agent-BFEY
F-SecureTrojan.TR/Dropper.Gen
VIPREGen:Variant.Lazy.430963
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Lazy.430963 (B)
IkarusTrojan.Win32.Glupteba
JiangminTrojan.Copak.cxtx
GoogleDetected
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.Kryptik.GIRH
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
MicrosoftTrojan:Win32/Glupteba.MT!MTB
ZoneAlarmVHO:Trojan.Win32.Copak.gen
GDataWin32.Trojan.PSE.11YPVZ
VaristW32/Kryptik.CIN.gen!Eldorado
AhnLab-V3Packed/Win.FJB.C5537712
Acronissuspicious
McAfeeTrojan-FVOQ!242E7D7961B6
MAXmalware (ai score=88)
VBA32Trojan.Khalesi
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.BF57 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.220157213.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Lazy.430963?

Lazy.430963 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment