Malware

Should I remove “Lazy.496728”?

Malware Removal

The Lazy.496728 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.496728 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Collects information to fingerprint the system
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Lazy.496728?


File Info:

name: D90390857921A5496E33.mlw
path: /opt/CAPEv2/storage/binaries/603c32a636dd281e587dc823523db2fe0278a7da9c79f6824f3aae607e08225b
crc32: ABC7A21B
md5: d90390857921a5496e33fa449fd39dd5
sha1: f099266e522819db0bb9c537412dfe45dde43bf2
sha256: 603c32a636dd281e587dc823523db2fe0278a7da9c79f6824f3aae607e08225b
sha512: 1479f6a65c55f2e73560fd6b67713930fe4716c2b995bdf3768b6a4d9f7017684d09832ea1dd7ce6592f3aa4e2cd7a9d5ea09874ebd3cabec03aa3f8c4269cff
ssdeep: 3072:WZK9UjrL5vSfmJtYTA1b5LLK26KC/gK8kV5ESE6asU9JrrDlnq:WQUTxSfmb4IpK26cKlV5I6I9h/lq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A44459B09086513ACA9842B14D96AD398F1EBC568B945DDB3189FCC63FB31C487ED50F
sha3_384: be97b71c41d67da03ca6e2608cc070092e039920b6ba0fc8baa6db0856b6e584c39a8aaeb2a33ff7388f6b0da64bb128
ep_bytes: 558bec51558f0510884300a110884300
timestamp: 2013-03-20 08:14:47

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft DirectPlay Voice Test
FileVersion: 5.03.2600.5512 (xpsp.080413-0845)
InternalName: dpvsetup.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: dpvsetup.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 5.03.2600.5512
Translation: 0x0409 0x04b0

Lazy.496728 also known as:

BkavW32.AIDetectMalware
AVGWin32:Gepys-J [Trj]
tehtrisGeneric.Malware
DrWebTrojan.Redirect.140
MicroWorld-eScanGen:Variant.Lazy.496728
SkyhighBehavesLike.Win32.Generic.dh
McAfeePWS-Zbot-FATW!D90390857921
MalwarebytesCrypt.Trojan.Malicious.DDS
ZillyaTrojan.ShipUp.Win32.16123
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0042f5761 )
K7GWTrojan ( 0042f5761 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36802.pu1@aan1lcfi
VirITTrojan.Win32.Generic.NDT
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.AXBQ
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Shipup-6804175-0
KasperskyTrojan.Win32.ShipUp.boh
BitDefenderGen:Variant.Lazy.496728
AvastWin32:Gepys-J [Trj]
TencentTrojan.Win32.Shipup.xf
EmsisoftGen:Variant.Lazy.496728 (B)
F-SecureTrojan.TR/Obfuscate.adhoum
BaiduWin32.Trojan.Agent.eq
VIPREGen:Variant.Lazy.496728
TrendMicroTROJ_AGENT_054753.TOMB
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.d90390857921a549
SophosTroj/Zbot-EHY
SentinelOneStatic AI – Malicious PE
JiangminTrojan/ShipUp.jk
GoogleDetected
AviraTR/Obfuscate.adhoum
MAXmalware (ai score=88)
Antiy-AVLTrojan/Win32.ShipUp
Kingsoftmalware.kb.a.1000
MicrosoftTrojanDropper:Win32/Gepys!pz
XcitiumTrojWare.Win32.Kryptik.AYQE@4wlbfl
ArcabitTrojan.Lazy.D79458
ZoneAlarmTrojan.Win32.ShipUp.boh
GDataWin32.Trojan.PSE1.53QUVM
VaristW32/Zbot.JC.gen!Eldorado
AhnLab-V3Trojan/Win32.Kuluoz.C257070
Acronissuspicious
ALYacGen:Variant.Lazy.496728
VBA32BScope.Malware-Cryptor.Hlux
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_AGENT_054753.TOMB
RisingTrojan.Kryptik!1.AB8B (CLASSIC)
YandexTrojan.GenAsa!JtzQGDDzcuw
IkarusTrojan.Win32.ShipUp
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.AYTK!tr
Cybereasonmalicious.57921a
DeepInstinctMALICIOUS

How to remove Lazy.496728?

Lazy.496728 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment