Malware

Lazy.47263 removal instruction

Malware Removal

The Lazy.47263 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.47263 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • CAPE detected the RedLine malware family

How to determine Lazy.47263?


File Info:

name: 4C1CF4036A8B1873ECF4.mlw
path: /opt/CAPEv2/storage/binaries/6ecdea61655863dfc39f4b035144f2790090d4741bc10b29ab6ecab041c889c4
crc32: F631EDF3
md5: 4c1cf4036a8b1873ecf4d1a7acff4cb0
sha1: 21d5cfa0e99b48ab456652ab0b78329ac77dc182
sha256: 6ecdea61655863dfc39f4b035144f2790090d4741bc10b29ab6ecab041c889c4
sha512: 294a8a5fcc60c357cb582682e20860815a3c8db75c08838d4728a13ec5f3431e560b4afa7b88bada926908390a922b6c7f4c51c52415b22d87a31cee7abeeb7d
ssdeep: 12288:7zxzTDWikLSb4NS7cxUX0SAr/wDB/gbYcxXnu1Sm:hDWHSb4NnZjSSbbo1j
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FFC4F102FD8588B2C6711C355929AB616539BA200F24CFDBE3D44E7DEA311D1BB31BA7
sha3_384: 9073c4a32affcc3dcbc7fc755f199633c80d54dbe5ba165979240638bbfcf3447822fa77f1617864f6ed35767b359fc1
ep_bytes: e864040000e988feffff3b0d68e64300
timestamp: 2021-06-11 09:16:47

Version Info:

0: [No Data]

Lazy.47263 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.47263
FireEyeGeneric.mg.4c1cf4036a8b1873
ZillyaTrojan.Agent.Win32.2205396
Cybereasonmalicious.0e99b4
CyrenW32/MSIL_Agent.BJO.gen!Eldorado
ESET-NOD32a variant of MSIL/Spy.Agent.CVT
APEXMalicious
KasperskyHEUR:Trojan-PSW.MSIL.Reline.gen
BitDefenderGen:Variant.Lazy.47263
AvastWin32:PWSX-gen [Trj]
EmsisoftGen:Variant.Lazy.47263 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
SophosGeneric ML PUA (PUA)
IkarusTrojan.MSIL.Spy
GDataMSIL.Trojan-Stealer.Redline.B
AviraHEUR/AGEN.1144456
MAXmalware (ai score=81)
MicrosoftTrojan:MSIL/Reline.AES!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R421303
BitDefenderThetaGen:NN.ZemsilF.34294.xu0@auRJX@o
ALYacGen:Variant.Lazy.47263
VBA32Trojan.MSIL.RedLine.Heur
MalwarebytesBackdoor.Bladabindi.SFX
RisingStealer.RedLine!1.DA64 (CLASSIC)
SentinelOneStatic AI – Malicious SFX
FortinetMSIL/Agent.DFY!tr.spy
AVGWin32:PWSX-gen [Trj]
PandaTrj/Genetic.gen

How to remove Lazy.47263?

Lazy.47263 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment