Malware

About “Lazy.477670” infection

Malware Removal

The Lazy.477670 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.477670 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Spanish (Modern)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics

How to determine Lazy.477670?


File Info:

name: 845165BAFE982DE13220.mlw
path: /opt/CAPEv2/storage/binaries/af67d95c48031517c02bc812abc3ca717d816545ef237b02e2718575a38b1ea1
crc32: 0BE759FE
md5: 845165bafe982de13220a2dba10723fa
sha1: ad479b58a6f09f53f4f47b69f5894993ec0186d6
sha256: af67d95c48031517c02bc812abc3ca717d816545ef237b02e2718575a38b1ea1
sha512: 387b5266fbf7d8e220ad30e5cb06f2fb337103183de82449f0a390a012d6c72904ede099897a6c53c78b9ae41ed9f20760f66a510d4a20b32d8c129d91ad4582
ssdeep: 384:/TTaCRq+Da8TJpFNk8TLZbjW+6W/Cz+AEuNelC8G3/R5:/3actaEFd/TCz+AEBQ8G/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F5F2F853FA9C49B6F3DA07714AB706E6967B7C220E31C80B098E3A2C1D7F94199B5713
sha3_384: 83d02b591ba74749e4a15202a38e3f766cfc66700912dc1b039a22295f3e96e4bd6b3f109849907fb37832d55549c605
ep_bytes: 9c60e80200000033c08bc483c004938b
timestamp: 2011-06-22 06:43:47

Version Info:

Comments:
CompanyName: Stepok Image Lab.
FileDescription: SCREEN2EXE / SCREEN2SWF
FileVersion: 3, 2, 0, 0
InternalName: ScreenProject
LegalCopyright: Copyright (C) 2008-2011, Stepok Image Lab.
LegalTrademarks:
OriginalFilename: ScreenProject.EXE
PrivateBuild:
ProductName: SCREEN2EXE / SCREEN2SWF
ProductVersion: 3, 2, 0, 0
SpecialBuild:
Translation: 0x0c0a 0x04b0

Lazy.477670 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.VBKrypt.ln5e
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.477670
FireEyeGeneric.mg.845165bafe982de1
SkyhighBehavesLike.Win32.Autorun.nz
ALYacGen:Variant.Lazy.477670
MalwarebytesGeneric.Malware/Suspicious
SangforSuspicious.Win32.Save.vb
AlibabaTrojanDownloader:Win32/Genome.0e736fbe
VirITTrojan.Win32.SHeur3.CGDQ
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Generik.GZILLLX
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R03BC0GBF24
AvastWin32:Evo-gen [Trj]
KasperskyTrojan-Downloader.Win32.Genome.ctwt
BitDefenderGen:Variant.Lazy.477670
NANO-AntivirusTrojan.Win32.VBKrypt.eayjh
TencentWin32.Trojan-Downloader.Genome.Wimw
EmsisoftGen:Variant.Lazy.477670 (B)
F-SecureTrojan.TR/VB.Downloader.Gen
DrWebTrojan.DownLoad2.38641
ZillyaDownloader.Genome.Win32.35125
TrendMicroTROJ_GEN.R03BC0GBF24
SophosMal/Generic-S
Paloaltogeneric.ml
JiangminTrojan/VBKrypt.bvle
VaristW32/VB-Downloader-Minimi-based!
AviraTR/VB.Downloader.Gen
MAXmalware (ai score=99)
Antiy-AVLTrojan[Downloader]/Win32.Genome
Kingsoftmalware.kb.a.995
MicrosoftTrojan:Win32/Multiverze
XcitiumMalware@#1ssk53crycqy2
ArcabitTrojan.Lazy.D749E6
ViRobotTrojan.Win32.A.Downloader.34309
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataGen:Variant.Lazy.477670
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.VBKrypt.R19658
McAfeeArtemis!845165BAFE98
GoogleDetected
TACHYONTrojan/W32.Small.34309
VBA32BScope.Trojan.Packed
Cylanceunsafe
PandaTrj/CI.A
ZonerProbably Heur.ExeHeaderL
RisingDownloader.Genome!8.142 (CLOUD)
YandexTrojan.DL.Genome!aee1LM8NGms
IkarusTrojan.Win32.VBKrypt
MaxSecureTrojan.Malware.3105053.susgen
FortinetW32/Genome.CTWT!tr.dldr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan[downloader]:MSOffice/Genome.ctwt

How to remove Lazy.477670?

Lazy.477670 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment