Malware

Lazy.445623 malicious file

Malware Removal

The Lazy.445623 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.445623 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Lazy.445623?


File Info:

name: D5D8A358BAECDA741691.mlw
path: /opt/CAPEv2/storage/binaries/8a363eeec231d28b9ea94df0fa008277239e9214222c8d6310420638e1286916
crc32: 1065AC53
md5: d5d8a358baecda7416915b14fd642068
sha1: 0c7b5533f9f7b6e4c08a41b6e3661b9afc06ae50
sha256: 8a363eeec231d28b9ea94df0fa008277239e9214222c8d6310420638e1286916
sha512: c97f1b5676c9236006585110928bcf1fba06f94f6da3cdc92cbc95c467a42d24c37ba58b28e1ff8e79a419f8a167e56c25e1e87f1b0c0d9cec9da90cd049ee98
ssdeep: 196608:cl9XDJMzE6e/UpSjFttho+Uir3Y9R7rsxfHnyid97Gn:a6eNTtUL9V2qS7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T168A6F1A3B52680F2E1390C3950226F76B7F972214B219AE767D0DDD55C331E2EE3A11B
sha3_384: 303f53f167add652b4ddb66a13b62e3cb55fdd287ced1da3eb3f440fe7d084f111eac6c05355885419ab6f20ece85765
ep_bytes: 53bb1332192ce843bae7ff415f66453b
timestamp: 2024-01-13 12:53:56

Version Info:

FileVersion: 9.8.8.0
FileDescription: ewee34
ProductName: hid4
ProductVersion: 9.8.8.0
CompanyName: k
LegalCopyright: aaaaa
Comments: 8
Translation: 0x0804 0x04b0

Lazy.445623 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.445623
ClamAVWin.Dropper.Tiggre-9845940-0
SkyhighBehavesLike.Win32.Generic.tc
ALYacGen:Variant.Lazy.445623
Cylanceunsafe
SangforTrojan.Win32.Save.BlackMoon
CrowdStrikewin/malicious_confidence_70% (D)
ArcabitTrojan.Lazy.D6CCB7
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.BlackMoon.D suspicious
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:Backdoor.Win32.Poison
BitDefenderGen:Variant.Lazy.445623
AvastWin32:Evo-gen [Trj]
TencentMalware.Win32.Gencirc.13fd353b
SophosGeneric ML PUA (PUA)
F-SecureTrojan.TR/Spy.Gen
VIPREGen:Variant.Lazy.445623
EmsisoftGen:Variant.Lazy.445623 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Spy.Gen
Antiy-AVLTrojan/Win32.FlyStudio.a
MicrosoftTrojan:Win32/Sabsik.FL.A!ml
ZoneAlarmUDS:Backdoor.Win32.Poison
GDataGen:Variant.Lazy.445623
McAfeeArtemis!D5D8A358BAEC
VBA32BScope.TrojanPSW.Coins
MalwarebytesGeneric.Trojan.Malpack.DDS
RisingTrojan.Generic@AI.98 (RDML:t0WG/aAj7SwDNHAllqnr7A)
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.121218.susgen
BitDefenderThetaGen:NN.ZexaF.36680.@F0@au3Z80lb
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.3f9f7b
DeepInstinctMALICIOUS

How to remove Lazy.445623?

Lazy.445623 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment