Malware

Lazy.336445 removal instruction

Malware Removal

The Lazy.336445 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.336445 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Lazy.336445?


File Info:

name: AACF4FB637B694CBDA1A.mlw
path: /opt/CAPEv2/storage/binaries/b7cb933f333a4780cc72583844895ed0346681f750bb733bf21acf84386ed0f0
crc32: D97C4B4E
md5: aacf4fb637b694cbda1a0efcef0eb662
sha1: baeac9659219fad392b487f74387d620d5e85127
sha256: b7cb933f333a4780cc72583844895ed0346681f750bb733bf21acf84386ed0f0
sha512: f8dc896fe91b676424ab027a14e795cb81a7bcc9ab1f555ed316eaad9f0cb50e6795acab8b6f342e9dc1d93f06d677088c033922597f6d202be249b5c8a3e7d3
ssdeep: 6144:UdXCHqZBkiey8o6ibQgiXLY7Vyk8b5CHJJ8hM8IP/F97Vw/XcdU:UVGkNiX6jt76/Xcm
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T16654AE5DED454BF2C38243B5990654C1BAD9D734237985F7122B820F036EAA8D2FB3AD
sha3_384: 11054639efbc840576d0d26d17b78f8511ba223b2268691d72ca813642cf883cbeaf7cf647aa18237143f0653e44214c
ep_bytes: c7fa9e7e97931af99272136880307bd2
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Lazy.336445 also known as:

BkavW32.AIDetectMalware
DrWebTrojan.PackedENT.123
MicroWorld-eScanGen:Variant.Lazy.336445
FireEyeGeneric.mg.aacf4fb637b694cb
SkyhighBehavesLike.Win32.Ctsinf.dh
McAfeeTrojan-FVOQ!AACF4FB637B6
MalwarebytesCrypt.Trojan.MSIL.DDS
VIPREGen:Variant.Lazy.336445
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
K7GWTrojan ( 005a45ef1 )
Cybereasonmalicious.637b69
BitDefenderThetaGen:NN.ZexaF.36802.r8Z@a4kX8Mg
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.GIFY
APEXMalicious
ClamAVWin.Packed.Zpack-10001780-0
KasperskyHEUR:Trojan.Win32.Copak.pef
BitDefenderGen:Variant.Lazy.336445
NANO-AntivirusTrojan.Win32.Selfmod.ilaxnd
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Copak.kf
TACHYONTrojan/W32.Selfmod
EmsisoftGen:Variant.Lazy.336445 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
ZillyaTrojan.Kryptik.Win32.4160185
Trapminemalicious.moderate.ml.score
SophosMal/Inject-GJ
IkarusTrojan.Win32.Cerber
JiangminTrojan.Selfmod.hw
GoogleDetected
AviraTR/Crypt.XPACK.Gen
VaristW32/Trojan.NJGF-3047
Antiy-AVLTrojan/Win32.Kryptik.girh
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Win32/Glupteba.MT!MTB
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
ArcabitTrojan.Lazy.D5223D
ZoneAlarmHEUR:Trojan.Win32.Copak.pef
GDataGen:Variant.Lazy.336445
CynetMalicious (score: 100)
AhnLab-V3Packed/Win.FJB.C5394144
Acronissuspicious
VBA32Trojan.Khalesi
MAXmalware (ai score=82)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.BF57 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.207078214.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudVirTool:Win/Obfuscate.FakeEp.DYN(dyn)

How to remove Lazy.336445?

Lazy.336445 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment