Trojan

Trojan:Win32/Laziok.A!dha removal guide

Malware Removal

The Trojan:Win32/Laziok.A!dha is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Laziok.A!dha virus can do?

  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to identify installed AV products by installation directory
  • Detects VirtualBox through the presence of a file
  • Detects VMware through the presence of a file
  • Creates a copy of itself
  • Deletes executed files from disk
  • Creates known Kraken mutexes

How to determine Trojan:Win32/Laziok.A!dha?


File Info:

name: 5638CA305D173DF49966.mlw
path: /opt/CAPEv2/storage/binaries/ff64135aad5ba767ba4252cb49289d6e359abb95697a6cd589ffd8abaf58842c
crc32: A6AB5ED3
md5: 5638ca305d173df49966b57c29149410
sha1: 3a5a4d127ef01ce7c269a9959246c24dd261aef0
sha256: ff64135aad5ba767ba4252cb49289d6e359abb95697a6cd589ffd8abaf58842c
sha512: 9efe94d83928a86765c4c8bbe7b7b8e5dca3d6730463136ab29a017e9ddfa221a8070a3d18a345f3cd3bd4c9f03c7fab081211eb848a2fec1b3b0a9d8e1eef4c
ssdeep: 1536:guESfiK2xko1dOtkL+JGoCMlFAoLizJ/dWcfdNDKmmLmYUvm3X2c5x1:gPz7xPYtcv64omd5KmmLmYUvm3X2cP1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T135B3D5A177C60915F7F3527928F216E3C93DB422CA78CE8B4787071E05E55A8C9E0BAD
sha3_384: 71beb8978d696289ff3fcfb7b3676936ed60fdf518ef4f0bc6f92f7dea2580b8a15f9cdcc4be9493c9c2b8f5cdc949d9
ep_bytes: 686c0500006800000000682cc74100e8
timestamp: 2015-02-26 06:23:17

Version Info:

0: [No Data]

Trojan:Win32/Laziok.A!dha also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Mint.Porcupine.gqW@amSY9jbag
FireEyeGeneric.mg.5638ca305d173df4
McAfeeArtemis!5638CA305D17
Cylanceunsafe
ZillyaTrojan.Laziok.Win32.1
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00510f3c1 )
AlibabaTrojan:Win32/Starter.ali2000005
K7GWTrojan ( 00510f3c1 )
Cybereasonmalicious.05d173
ArcabitTrojan.Mint.Porcupine.ED1430D
BitDefenderThetaGen:NN.ZexaF.36350.gqW@amSY9jb
VirITTrojan.Win32.Generic.AXJM
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Laziok.A
APEXMalicious
KasperskyTrojan.Win32.Laziok.a
BitDefenderGen:Heur.Mint.Porcupine.gqW@amSY9jbag
NANO-AntivirusTrojan.Win32.Laziok.doklkg
AvastWin32:Malware-gen
TencentWin32.Trojan.Laziok.Cgow
EmsisoftGen:Heur.Mint.Porcupine.gqW@amSY9jbag (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen7
DrWebTrojan.DownLoader12.55754
VIPREGen:Heur.Mint.Porcupine.gqW@amSY9jbag
TrendMicroTROJ_FORUCON.BME
McAfee-GW-EditionBehavesLike.Win32.Generic.cm
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.bbamx
WebrootW32.Gen.SB
GoogleDetected
AviraTR/Crypt.XPACK.Gen7
Antiy-AVLTrojan/Win32.AGeneric
XcitiumMalware@#2lo08g1o89xr5
MicrosoftTrojan:Win32/Laziok.gen.A!dha
ZoneAlarmTrojan.Win32.Laziok.a
GDataGen:Heur.Mint.Porcupine.gqW@amSY9jbag
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Laziok.R139287
VBA32BScope.Trojan.MulDrop
ALYacGen:Heur.Mint.Porcupine.gqW@amSY9jbag
MAXmalware (ai score=100)
MalwarebytesMalware.Heuristic.1008
PandaTrj/Genetic.gen
ZonerTrojan.Win32.32038
TrendMicro-HouseCallTROJ_FORUCON.BME
RisingMalware.Undefined!8.C (TFE:4:0looRVkIBcR)
YandexTrojan.Agent!ApUwt3OZdAU
IkarusTrojan.Win32.Laziok
FortinetW32/Laziok.A!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan:Win32/Laziok.A!dha?

Trojan:Win32/Laziok.A!dha removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment