Malware

Lazy.414556 removal

Malware Removal

The Lazy.414556 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.414556 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Lazy.414556?


File Info:

name: 06D7110E9D657DA12263.mlw
path: /opt/CAPEv2/storage/binaries/1e7996ad032820eb64c20c6472f3bd32173d6841f76df4d24a7da3b487c64dd7
crc32: 87B4092D
md5: 06d7110e9d657da122633d5ffd967fa0
sha1: c24c742dbbe8908fd58aca0c7fa726ee7eebf861
sha256: 1e7996ad032820eb64c20c6472f3bd32173d6841f76df4d24a7da3b487c64dd7
sha512: 6d585e5ff88a619174f4bc5b11986ef66b0bdad461d2bed0be415a1c44b3d9192a31c0c48cd98a353acc1de5a673e845b8c128b03d12e0d7f3c907102e2d3b0e
ssdeep: 98304:7xXCDQ9dZUSopeZwfLKeQVhnBhBctv6HJ1oCsKmteZ2nS2wQ1tIv:74DSwSoMZwfLiHcEprsKmte32wwK
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T16C26E002FEC08762D67D917E4A9FB6664E92BC05D9609EA331B7C75E3C7B80A7CC5006
sha3_384: 8960b63d3c2125fca4cae707624fd853bc08e0b8ad6bb1c3d89e2bc4c6b7254ce742a2c72b3a2ff8f1909425e36338c3
ep_bytes: 60be37bfd24148f7d0426189d048ba00
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Lazy.414556 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Copak.4!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Lazy.414556
SkyhighBehavesLike.Win32.Generic.rh
McAfeeGenericRXAA-FA!06D7110E9D65
MalwarebytesTrojan.MalPack.Generic
VIPREGen:Variant.Lazy.414556
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005aef1b1 )
AlibabaTrojan:Win32/Coinminer.ffddabc7
K7GWTrojan ( 005aef1b1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Lazy.D6535C
BitDefenderThetaGen:NN.ZexaF.36680.@pZ@aGXXzDe
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.ECAV
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:Trojan.Win32.Copak
BitDefenderGen:Variant.Lazy.414556
NANO-AntivirusTrojan.Win32.Razy.keyuwv
AvastWin32:Evo-gen [Trj]
RisingTrojan.Kryptik!1.D12D (CLASSIC)
EmsisoftGen:Variant.Lazy.414556 (B)
F-SecureTrojan.TR/Injector.twqki
ZillyaTrojan.Injector.Win32.1728845
TrendMicroTROJ_GEN.R049C0RL323
SophosMal/EncPk-F
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraTR/Injector.twqki
MAXmalware (ai score=83)
Antiy-AVLTrojan/Win32.Injector
XcitiumPacked.Win32.MUPX.Gen@24tbus
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmUDS:Trojan.Win32.Copak
GDataGen:Variant.Lazy.414556
VaristW32/Copak.F.gen!Eldorado
AhnLab-V3Trojan/Win.Generic.R554362
VBA32Trojan.Copak
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R049C0RL323
TencentTrojan.Win32.Tiggre.ka
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/GenKryptik.CRNJ!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS

How to remove Lazy.414556?

Lazy.414556 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment