Malware

Lazy.336445 removal guide

Malware Removal

The Lazy.336445 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.336445 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Creates a copy of itself
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Lazy.336445?


File Info:

name: 6BB0E2B1AE78B79AED0F.mlw
path: /opt/CAPEv2/storage/binaries/0febe21afad603c77b5d6e244c72302aede0c3bd7b455cecffa414e3e063b0ad
crc32: 2DE56743
md5: 6bb0e2b1ae78b79aed0fc1c6967f5d7a
sha1: 2a4504a0671a432a76a731044044a229ad542ec4
sha256: 0febe21afad603c77b5d6e244c72302aede0c3bd7b455cecffa414e3e063b0ad
sha512: 61714e37f210a3a2ca82c10dfbd2bd4e2f9954a73c26775e1773708bb72ecd041f7d82daf21fe060f4f299eb962712502cfb4df7e797bfb199f92f7fcd26f209
ssdeep: 6144:i1yKATPLb6SMqsFyF2koeXx783SF97Vw/XcdU:i1yKAzLrM98zXxg3+76/Xcm
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T17954AEAF774517A2C280023136375CC6EA3D92BD52BEE4A4A45C9C1E1379F2D53B32E6
sha3_384: 1393c7a759fe8c864f28045b8e9c82157eb75d9863325c6d84df33efb6dda58ec6b3a21df07f9435acdaa5147e4fd270
ep_bytes: f70e912da76715aaa2861c3bb0c47481
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Lazy.336445 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.Siggen24.48488
MicroWorld-eScanGen:Variant.Lazy.336445
FireEyeGeneric.mg.6bb0e2b1ae78b79a
SkyhighBehavesLike.Win32.Ctsinf.dh
McAfeeTrojan-FVOQ!6BB0E2B1AE78
MalwarebytesCrypt.Trojan.MSIL.DDS
VIPREGen:Variant.Lazy.336445
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
K7GWTrojan ( 005a45ef1 )
Cybereasonmalicious.0671a4
ArcabitTrojan.Lazy.D5223D
BitDefenderThetaGen:NN.ZexaF.36680.r8Z@a4kX8Mg
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GIFY
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Zpack-10001780-0
KasperskyHEUR:Trojan.Win32.Copak.pef
BitDefenderGen:Variant.Lazy.336445
NANO-AntivirusTrojan.Win32.Selfmod.khjmsl
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Copak.kf
EmsisoftGen:Variant.Lazy.336445 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
SophosMal/Inject-GJ
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Copak.cpjf
VaristW32/Trojan.NJGF-3047
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=83)
Antiy-AVLTrojan/Win32.Kryptik.girh
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
MicrosoftTrojan:Win32/Glupteba.MT!MTB
ZoneAlarmHEUR:Trojan.Win32.Copak.pef
GDataGen:Variant.Lazy.336445
GoogleDetected
AhnLab-V3Packed/Win.FJB.C5394144
Acronissuspicious
VBA32Trojan.Khalesi
ALYacGen:Variant.Lazy.336445
TACHYONTrojan/W32.Selfmod
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B34D (CLASSIC)
YandexTrojan.Kryptik!W1X0LsYpLzI
IkarusTrojan.Win32.Cerber
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Lazy.336445?

Lazy.336445 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment