Malware

Ser.Lazy.1633 malicious file

Malware Removal

The Ser.Lazy.1633 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ser.Lazy.1633 virus can do?

  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Estonian
  • The binary likely contains encrypted or compressed data.
  • .NET file is packed/obfuscated with SmartAssembly
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Ser.Lazy.1633?


File Info:

name: 3EE3BA8F7E35D5201222.mlw
path: /opt/CAPEv2/storage/binaries/27f21291d8c4e3a64482bca7c38dce31e05b3c41c2c1a5c5a911390a0ea07576
crc32: 3D9EEBB7
md5: 3ee3ba8f7e35d5201222c4636c9a3ede
sha1: a2898abe289d95cf96cf720326dcd6ed0e89bdd3
sha256: 27f21291d8c4e3a64482bca7c38dce31e05b3c41c2c1a5c5a911390a0ea07576
sha512: 374d5674de25472b92df0aa19e03abd96d8163e218f4c192b1abd81244a3011fbb559a6ebbd617c37a027f4774191b922c14843eb7d4ebf60c858872783affc9
ssdeep: 12288:ThJ4i8p8eWD8vEhbYX/qLIBI5OLpdNIrd4Dx5OLpdNIrd4DA:Ui8WBhbEqTmXIrdCmXIrdN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T186E4E0C3758CA5A0E4B90934057B5C211AA6AD9E47C9FA0F36CB3B1E1EB73C25157AC3
sha3_384: ee07c233c71fbfae2084102af8e80765efab10d1ee93203fda32538b32808444f5d34bd441b154538a19621cf4a93731
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-09-07 11:13:08

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Internet Explorer Add-on Installer
LegalCopyright: © Microsoft Corporation. All rights reserved.
ProductName: Internet Explorer
ProductVersion: 11.00.19041.1
Translation: 0x0409 0x04b0
FileVersion: 11.00.19041.1 (WinBuild.160101.0800)
InternalName: ieinstal.exe
OriginalFilename: ieinstal.exe

Ser.Lazy.1633 also known as:

BkavW32.AIDetectNet.01
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Ser.Lazy.1633
FireEyeGeneric.mg.3ee3ba8f7e35d520
McAfeeArtemis!3EE3BA8F7E35
SangforTrojan.Win32.Save.a
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.FPT
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Spy.MSIL.Stealer.gen
BitDefenderGen:Variant.Ser.Lazy.1633
AvastWin32:RATX-gen [Trj]
Ad-AwareGen:Variant.Ser.Lazy.1633
EmsisoftGen:Variant.Ser.Lazy.1633 (B)
DrWebTrojan.Siggen18.44397
VIPREGen:Variant.Ser.Lazy.1633
Trapminemalicious.moderate.ml.score
SophosML/PE-A + Mal/MSIL-VD
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Ser.Lazy.1633
WebrootW32.Trojan.Gen
AviraTR/Drop.Agent.xvfta
ArcabitTrojan.Ser.Lazy.D661
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GoogleDetected
Acronissuspicious
ALYacGen:Variant.Ser.Lazy.1633
MAXmalware (ai score=80)
FortinetMSIL/Agent.FPT!tr
BitDefenderThetaGen:NN.ZemsilF.34646.Pm0@aC0TGYfO
AVGWin32:RATX-gen [Trj]
Cybereasonmalicious.e289d9

How to remove Ser.Lazy.1633?

Ser.Lazy.1633 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment