Malware

Lazy.414556 removal guide

Malware Removal

The Lazy.414556 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.414556 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Lazy.414556?


File Info:

name: D79F286BC77F5B62D5AD.mlw
path: /opt/CAPEv2/storage/binaries/e6a3619264250b2816d570e1acaaf5e54206e8288516aadd786a5e9a03abc9b4
crc32: 070259A5
md5: d79f286bc77f5b62d5ade2aa9bd4a881
sha1: def87703c639abf9c689ebc7fd8b548672daf3bf
sha256: e6a3619264250b2816d570e1acaaf5e54206e8288516aadd786a5e9a03abc9b4
sha512: cace3fc365bbf73ac716db5f333c7ca310a7c7240a26c2c2324c6baf969fbd3afa2aef51aabcabe8962015b6be7eea060a5a2e454ea7b29b7e82d82baa9bd5e3
ssdeep: 3072:ta79YfTZvjZQ9FiFhOqTB7xChCB4jVFHLTznJZD8j+rMNK8P5eSC2:E7KbxqOOqohRjnL/n7iMCvP5eSv
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1F1E3C06FF68D1771C68103F61B5B89D6B729A4B823A982F0B42DD05E1326F7C42B3794
sha3_384: 855a4cba18267f4a6c0ba91818431706d6b991088e56590d3314367608a59d765956bc19767f65f1574014b8a338a2da
ep_bytes: b8000000005701f281c21265eb5668a8
timestamp: 1974-02-09 00:00:00

Version Info:

0: [No Data]

Lazy.414556 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.414556
SkyhighBehavesLike.Win32.Generic.ch
ALYacGen:Variant.Lazy.414556
Cylanceunsafe
VIPREGen:Variant.Lazy.414556
SangforSuspicious.Win32.Save.a
BitDefenderGen:Variant.Lazy.414556
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/GenKryptik.FGBK
APEXMalicious
ClamAVWin.Packed.Lazy-10004830-0
RisingTrojan.Injector!1.C865 (CLASSIC)
F-SecureTrojan.TR/Injector.qlchq
DrWebTrojan.Packed2.43250
FireEyeGeneric.mg.d79f286bc77f5b62
EmsisoftGen:Variant.Lazy.414556 (B)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=80)
GoogleDetected
AviraTR/Injector.qlchq
VaristW32/Kryptik.JCS.gen!Eldorado
Antiy-AVLTrojan/Win32.Injector
Kingsoftmalware.kb.a.997
MicrosoftTrojan:Win32/Wacatac.B!ml
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Lazy.D6535C
GDataGen:Variant.Lazy.414556
CynetMalicious (score: 100)
DeepInstinctMALICIOUS
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.MalPack.Generic
PandaTrj/Genetic.gen
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.FFP!tr
BitDefenderThetaGen:NN.ZexaF.36792.jmY@aS2JtN
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Lazy.414556?

Lazy.414556 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment