Malware

Should I remove “Lazy.449442”?

Malware Removal

The Lazy.449442 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.449442 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Lazy.449442?


File Info:

name: 6AABD8587EC0E0E79B5E.mlw
path: /opt/CAPEv2/storage/binaries/3b9a3ec87c5b32c0721cfed7cf4902ae303e126d51cd893c19af5894167881dc
crc32: 85194562
md5: 6aabd8587ec0e0e79b5e4aa24ecbba63
sha1: c72cd85f2d894acadc98d0ce56a1f0f9d0db3697
sha256: 3b9a3ec87c5b32c0721cfed7cf4902ae303e126d51cd893c19af5894167881dc
sha512: 2dac92089948ea645dc1fa2cef8c44dceff6eb55eca0ca4cac42fc2995b89e4475f213dc12609dc52da1b0932f15526dac52176c4b6358c732a1549ae695fa8c
ssdeep: 3072:NDosKDaohUvimLmB+O5IKKp8akhjKJZCkZscAeaMy6Vjk1gqiXKcduXK/l3CuWex:uivimLfO5eGV6ZZscjaMy6xFy03tfXp
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1D124C0CA988CBA33D34D067069A21496F30B925543BB939AB0C5D56E1DB1FFB016E33D
sha3_384: 2a4305b4edbecc62bb728eb53f2371bbb1b7beab6710327f9819c5735ffeca5b303c715efe9467661dbcc840c3a56d48
ep_bytes: 098055fd59e9d17a5c08d8eb4e4ab051
timestamp: 1971-05-16 00:00:00

Version Info:

0: [No Data]

Lazy.449442 also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Lazy.449442
SkyhighBehavesLike.Win32.Generic.dc
McAfeeTrojan-FVOQ!6AABD8587EC0
MalwarebytesCrypt.Trojan.MSIL.DDS
ZillyaTrojan.KryptikAGen.Win32.23343
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
K7GWTrojan ( 005a45ef1 )
Cybereasonmalicious.f2d894
ArcabitTrojan.Lazy.D6DBA2
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik_AGen.BGU
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Razy-9938100-0
KasperskyVHO:Trojan.Win32.Copak.gen
BitDefenderGen:Variant.Lazy.449442
NANO-AntivirusTrojan.Win32.Selfmod.iubejy
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Crypt.hbw
EmsisoftGen:Variant.Lazy.449442 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.PackedENT.123
VIPREGen:Variant.Lazy.449442
SophosMal/Inject-GJ
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Selfmod.kfb
VaristW32/Trojan.NJGF-3047
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.Kryptik.girh
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
MicrosoftTrojan:Win32/Glupteba.MT!MTB
ZoneAlarmVHO:Trojan.Win32.Copak.gen
GDataWin32.Trojan.PSE.11XGYE9
GoogleDetected
AhnLab-V3Packed/Win.FJB.C5539024
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36680.n8W@a83RoFe
TACHYONTrojan/W32.Selfmod
VBA32Trojan.Khalesi
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B34D (CLASSIC)
IkarusTrojan.Win32.Glupteba
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Lazy.449442?

Lazy.449442 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment