Malware

What is “Lazy.444966”?

Malware Removal

The Lazy.444966 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.444966 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Lazy.444966?


File Info:

name: FBF5F343037F1251CE34.mlw
path: /opt/CAPEv2/storage/binaries/5d086c47e707dea1a609baa3f68cafe450aa27256b4c8a7a17bb8b891e43a202
crc32: 91C03A84
md5: fbf5f343037f1251ce34da7fb91b30b2
sha1: c700b9049510302c5d4c76a554e0047101c446d0
sha256: 5d086c47e707dea1a609baa3f68cafe450aa27256b4c8a7a17bb8b891e43a202
sha512: 2fc0a8d6f6c18c3ffcde8c4bf596074ca0d803ff1de028145d46ac79178fd730e6fb17a8cde91b3c9aacc1bc7db414d29f76c93f9c5e2cb274eeae7a8d000e0d
ssdeep: 6144:vnwl+M0ev0eUUtnyDfitMbrOfSWMlAWCX79+1lVx:YUWVyWmbqElAWdlVx
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T11B44AEAF7C840771C2D502F1A40B45EBCB58452E13EB46B1D4EF932B0EA69E443BB9D6
sha3_384: 9836dd9cc61c63c796f7ba758bd60890931826961ae12c455987c9019d805739be2b84b7e59bb91508ab129cbc52c7fb
ep_bytes: dcb395288cda11af893b183e9b797084
timestamp: 1971-05-16 00:00:00

Version Info:

0: [No Data]

Lazy.444966 also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Lazy.444966
FireEyeGeneric.mg.fbf5f343037f1251
SkyhighBehavesLike.Win32.Generic.dc
McAfeeTrojan-FVOQ!FBF5F343037F
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
K7GWTrojan ( 005a45ef1 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Lazy.D6CA26
BitDefenderThetaGen:NN.ZexaF.36680.q8Y@a4B08Bk
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik_AGen.BGU
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Razy-9828382-0
KasperskyUDS:Trojan.Win32.Copak.bhluu
BitDefenderGen:Variant.Lazy.444966
AvastWin32:Evo-gen [Trj]
EmsisoftGen:Variant.Lazy.444966 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Siggen24.57202
VIPREGen:Variant.Lazy.444966
SophosTroj/Agent-BFIJ
IkarusTrojan-Downloader.Win32.FakeAlert
VaristW32/Trojan.NJGF-3047
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=82)
Antiy-AVLTrojan/Win32.Kryptik.girh
Kingsoftmalware.kb.a.999
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
MicrosoftTrojan:Win32/Glupteba.MT!MTB
ZoneAlarmUDS:Trojan.Win32.Copak.bhluu
GDataWin32.Trojan.PSE.1ICMUE5
GoogleDetected
AhnLab-V3Packed/Win.FJB.C5394144
Acronissuspicious
VBA32Trojan.Khalesi
ALYacGen:Variant.Lazy.444966
TACHYONTrojan/W32.Selfmod
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B34D (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS

How to remove Lazy.444966?

Lazy.444966 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment