Malware

What is “Lazy.96968”?

Malware Removal

The Lazy.96968 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.96968 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Lazy.96968?


File Info:

name: DB66871C7E0F30C54956.mlw
path: /opt/CAPEv2/storage/binaries/10c7ab7c0fa2d5799782116025cf7c816a092c2c4932f047a36e8bde5cb8b994
crc32: 3550EAAF
md5: db66871c7e0f30c549567b002174647e
sha1: 2788117cdf13a240471112ae4b2d3f02565ab71f
sha256: 10c7ab7c0fa2d5799782116025cf7c816a092c2c4932f047a36e8bde5cb8b994
sha512: 5dc7b05dd8b165b97ca6360d30c7da0c5ce8d04f25d126c42bdd1b40a8e60b8e6cd0cf9c7dfdf68c251323d785a72b59b2701252823c325d1ac7cf5a8c6fe013
ssdeep: 12288:BILn6MEfztqUnUxs9iIoDyJRj86dMDexWcAch4tUTc6SDhVqkJZ9:BcJEhqW6UiIouJRj8qMDeccFh4ec7h4a
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17AD4BE057381FA6EE44102F14924FD6C0DA659F1DBEF82F7B3B42E2D0D626D105B87AA
sha3_384: b790fe2593435ec8d92bc072735c8e0ad798ea83dbd70371663c39224cc9fa83bd621b5ed1b17a89d0f48ae5652eb4a9
ep_bytes: e8e5040000e974feffff558beceb0dff
timestamp: 2022-01-11 04:07:25

Version Info:

CompanyName: AnyDesk Software GmbH
FileDescription: AnyDesk
FileVersion: 6.3.2
ProductName: AnyDesk
ProductVersion: 6.3
LegalCopyright: (C) 2021 AnyDesk Software GmbH
Translation: 0x0409 0x04e4

Lazy.96968 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Stealer.l!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.96968
FireEyeGeneric.mg.db66871c7e0f30c5
CylanceUnsafe
SangforTrojan.Win32.Stealer.gen
K7AntiVirusTrojan ( 005884af1 )
AlibabaTrojanSpy:Win32/Raccoon.3a217fb3
CrowdStrikewin/malicious_confidence_70% (D)
BitDefenderThetaGen:NN.ZexaF.34114.Ly0@aO897Rok
CyrenW32/Razy.HR.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNYX
TrendMicro-HouseCallTROJ_GEN.R002H0DAB22
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
BitDefenderGen:Variant.Lazy.96968
ViRobotTrojan.Win32.Z.Sabsik.615936
RisingBackdoor.NanoBot!8.28C (CLOUD)
Ad-AwareGen:Variant.Lazy.96968
EmsisoftGen:Variant.Lazy.96968 (B)
DrWebTrojan.PWS.Steam.24797
McAfee-GW-EditionBehavesLike.Win32.Generic.jh
SophosMal/Generic-S
APEXMalicious
AviraTR/Kryptik.wnpsx
Antiy-AVLTrojan/Generic.ASMalwS.3504F08
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Raccoon.DR!MTB
GDataWin32.Trojan.PSE.PZ7YYH
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.PWSX-gen.C4909113
McAfeeArtemis!DB66871C7E0F
VBA32BScope.TrojanSpy.Bobik
MalwarebytesSpyware.RedLineStealer
TencentWin32.Trojan-spy.Stealer.Wstq
YandexTrojan.GenKryptik!I1dT7UM5u34
MAXmalware (ai score=82)
FortinetW32/GenKryptik.FLKJ!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml

How to remove Lazy.96968?

Lazy.96968 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment