Malware

Lazy.501056 removal instruction

Malware Removal

The Lazy.501056 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.501056 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Lazy.501056?


File Info:

name: 1EB9174DCE4F38E5DC63.mlw
path: /opt/CAPEv2/storage/binaries/b3ac9483d6aa61b38caaa11797aad8af413e54a8597ab1b27c3229555dd96e12
crc32: 15D5F1F0
md5: 1eb9174dce4f38e5dc63d35ad2518df5
sha1: 6242d8b400a0dd8235ac99793af3efd4a56f33d7
sha256: b3ac9483d6aa61b38caaa11797aad8af413e54a8597ab1b27c3229555dd96e12
sha512: 7694b39aa3bc5958b8e056a3f4ac70a250ccd268ebb5c1b2046b2f4820893d500709cffa87ba16ef76ace019505f5e27731bc59b316a948caf0da7d9f2145c83
ssdeep: 384:UATttSPw84JRFnYJz7sto9KJzq98kENZT/RsaV:BEw84DJ3om298TWaV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T195A2C4BA1AD1793DE2724E3645F3C385A874BC222C59850E7D4DF60D783FA4368E1B1A
sha3_384: e33ccc4b354a2aa182806ced71bcdce9f76b6d1d82d0dbec731024bc2b09d4a8ea3e7017300db02d4fdf6b51d5c8886e
ep_bytes: 60be008040008dbe0090ffff57eb0b90
timestamp: 1995-08-29 04:02:04

Version Info:

FileDescription: JuJu
FileVersion: 2.1.2.11
LegalCopyright: Copyright 2009-2013 all authors
OriginalFilename: JuJu.exe
ProductName: JuJu
ProductVersion: 2.1.2.11
CompanyName: JuJu corporation
Translation: 0x0411 0x04b2

Lazy.501056 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
DrWebTrojan.DownLoader11.30467
MicroWorld-eScanGen:Variant.Lazy.501056
FireEyeGeneric.mg.1eb9174dce4f38e5
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Lazy.501056
K7AntiVirusTrojan ( 004a8f1e1 )
K7GWTrojan ( 004a8f1e1 )
BitDefenderThetaGen:NN.ZexaF.36804.bmLfaSmp5mfi
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.CKFL
APEXMalicious
TrendMicro-HouseCallTROJ_UPATRE.SM37
AvastWin32:Evo-gen [Trj]
ClamAVWin.Packed.Upatre-9952430-0
KasperskyTrojan-Ransom.Win32.Cryptodef.bcf
BitDefenderGen:Variant.Lazy.501056
NANO-AntivirusTrojan.Win32.Cryptodef.demivm
TencentMalware.Win32.Gencirc.10bfbdb4
EmsisoftGen:Variant.Lazy.501056 (B)
GoogleDetected
F-SecureTrojan.TR/AD.Yarwi.hifnv
BaiduWin32.Trojan-Downloader.Waski.a
ZillyaTrojan.Cryptodef.Win32.2990
TrendMicroTROJ_UPATRE.SM37
Trapminemalicious.moderate.ml.score
SophosMal/Zbot-QL
IkarusTrojan.Win32.Bublik
JiangminTrojan.Cryptodef.agg
WebrootW32.Trojan.Gen
VaristW32/Waski.T.gen!Eldorado
AviraTR/AD.Yarwi.hifnv
Antiy-AVLTrojan/Win32.Kryptik
Kingsoftmalware.kb.b.980
MicrosoftTrojan:Win32/Zbot.svfs!MTB
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Lazy.D7A540
ZoneAlarmTrojan-Ransom.Win32.Cryptodef.bcf
GDataWin32.Trojan-Downloader.Upatre.BK
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Cryptodef.C5600230
Acronissuspicious
VBA32TrojanDownloader.Upatre
ALYacGen:Variant.Lazy.501056
Cylanceunsafe
PandaTrj/Genetic.gen
RisingDownloader.Waski!8.184 (TFE:5:7tpvb6UfNTT)
YandexTrojan.Cryptodef!o1mHsAATruc
MAXmalware (ai score=81)
FortinetW32/Waski.A!tr.dldr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS

How to remove Lazy.501056?

Lazy.501056 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment