Malware

Lazy.90965 removal instruction

Malware Removal

The Lazy.90965 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.90965 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Lazy.90965?


File Info:

name: FF26560EB5D7CF121AE2.mlw
path: /opt/CAPEv2/storage/binaries/880ec4d8efd5463e1a669442734ab13fb67fe99dba9c3d180f9f92875f109be1
crc32: B052E107
md5: ff26560eb5d7cf121ae2be644e56208b
sha1: 8a2e4fdb42a543a60dcc0ff565ccf7443098013c
sha256: 880ec4d8efd5463e1a669442734ab13fb67fe99dba9c3d180f9f92875f109be1
sha512: 3ec39a8014aa7f9269e94b57bd481af15c788cb44bf0390a412db20a4067119321ae40500f76c96440635d8e116b3d96be00b6a95c56143211b4168ab858692f
ssdeep: 3072:ket4CckSPjCAfRsfX6HDN1ACIZT537+GmzlBIfTNwM6JbGqrP4ckSPjCAfRsfX:dBePrfRZDN1ACA53pmRpP4ePrfR
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T193E47D26A0C30377C1497EBD0F4446E5F773A8282A22D0F773D82A4F8D6EA557E28579
sha3_384: 1cf2a5e56494903d4422a141cc28e94ad76096588dc875f7eb7a20cb3743e09c9455a2c96765aafe9ff99109e913054a
ep_bytes: 5589e5c605c0d140000168d07241006a
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Lazy.90965 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.90965
FireEyeGeneric.mg.ff26560eb5d7cf12
ALYacGen:Variant.Lazy.90965
CylanceUnsafe
ZillyaTrojan.Injector.Win32.1316182
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00539ec91 )
K7GWTrojan ( 00539ec91 )
CyrenW32/Sabsik.X.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
KasperskyTrojan.Win32.Copak.kvyc
BitDefenderGen:Variant.Lazy.90965
AvastWin32:Evo-gen [Susp]
TencentMalware.Win32.Gencirc.10cfcb31
Ad-AwareGen:Variant.Lazy.90965
EmsisoftGen:Variant.Lazy.90965 (B)
McAfee-GW-EditionBehavesLike.Win32.BadFile.jz
SophosMal/Generic-S
IkarusTrojan.Win32.Injector
GDataGen:Variant.Lazy.90965
JiangminTrojan.Copak.bjzg
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASMalwS.34FB63D
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C3368260
McAfeeGenericRXRK-AF!FF26560EB5D7
VBA32Trojan.Copak
MalwarebytesTrojan.Injector
RisingSpyware.Agent!8.C6 (TFE:dGZlOgVotIV61wP8XQ)
YandexTrojan.Injector!ysvB+bKvh5g
FortinetW32/Injector.DZQA!tr
BitDefenderThetaGen:NN.ZexaF.34114.RyZ@aa5MOZf
AVGWin32:Evo-gen [Susp]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Lazy.90965?

Lazy.90965 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment