Malware

What is “Lazy.336445”?

Malware Removal

The Lazy.336445 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.336445 virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Lazy.336445?


File Info:

name: 012173B029E889EA173F.mlw
path: /opt/CAPEv2/storage/binaries/b6a76035c9b70f8c863de5eae7d97977bcb1c5cf6596d915d156a410982ed0be
crc32: 10FD5D87
md5: 012173b029e889ea173f7f56198dea67
sha1: 8c0b8c513bcd9b7f7217553557c3a5e0c941cee4
sha256: b6a76035c9b70f8c863de5eae7d97977bcb1c5cf6596d915d156a410982ed0be
sha512: 204e2f33122a5bb333cd2dbca0ddd1175ac2f434a590a3c221207d89639d702b76855616086f4c13dbaa45db0edd68b91c0b530d4109e333b4e7d0756036b3b4
ssdeep: 6144:SreyMnV5FqyeCJRhvIAdAYO6/ndHIF97Vw/XcdU:lyoV5FXJnwLp61M76/Xcm
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T12D54C05FB3050BE2C3900277214779866B18A0BD63FB86F024F983DD9356968867F5BE
sha3_384: deeb9ab8bcf44ba861c7379ea1ef510b8e1086c0e6e83bfcd15d6098d0bb6d9c81bfcb0e881c4e83bf2e9785885487ba
ep_bytes: 367f504c6616d4cb63f7dd5a71b5b5e0
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Lazy.336445 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.336445
SkyhighBehavesLike.Win32.Generic.dh
McAfeeTrojan-FVOQ!012173B029E8
MalwarebytesCrypt.Trojan.MSIL.DDS
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
K7GWTrojan ( 005a45ef1 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Lazy.D5223D
BitDefenderThetaGen:NN.ZexaF.36608.r8Z@a4kX8Mg
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GIFY
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Zpack-10001780-0
KasperskyHEUR:Trojan.Win32.Copak.pef
BitDefenderGen:Variant.Lazy.336445
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Copak.kf
EmsisoftGen:Variant.Lazy.336445 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
VIPREGen:Variant.Lazy.336445
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.012173b029e889ea
SophosMal/Inject-GJ
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.gdfcx
VaristW32/Trojan.NJGF-3047
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=87)
Antiy-AVLTrojan/Win32.Kryptik.girh
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
MicrosoftTrojan:Win32/Glupteba.MT!MTB
ZoneAlarmHEUR:Trojan.Win32.Copak.pef
GDataGen:Variant.Lazy.336445
GoogleDetected
AhnLab-V3Packed/Win.FJB.C5394144
Acronissuspicious
VBA32Trojan.Khalesi
ALYacGen:Variant.Lazy.336445
TACHYONTrojan/W32.Selfmod
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B34D (CLASSIC)
IkarusTrojan.Win32.Cerber
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS

How to remove Lazy.336445?

Lazy.336445 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment