Malware

Lazy.449442 (file analysis)

Malware Removal

The Lazy.449442 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.449442 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Lazy.449442?


File Info:

name: DADD4DE8E0624EF2E2EE.mlw
path: /opt/CAPEv2/storage/binaries/60dbb34dc4970783099c80480f2b72b83d21259bdb7ec89a9bbe1649f65e6b63
crc32: C4CDB216
md5: dadd4de8e0624ef2e2ee10082c4a4ce2
sha1: b5aeb5630d18f4836f356e4ab810d619028d1201
sha256: 60dbb34dc4970783099c80480f2b72b83d21259bdb7ec89a9bbe1649f65e6b63
sha512: fd37f942f8bef49e24bfe3c768507f3afd0cdf936caf72c38f2d712387b963d25eeb2b4eb0d21c5c7be56302113185682fed1cfe18339fc138734134d518b6e3
ssdeep: 6144:JPXBhSiMnHY25AxvgwcSbr2agjur6DtfXp:J5h8ixvwS3TKtfp
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1AB24CFAD7489EEFCC9DC15BB5C6E308A86C8227F166790ADE252D70D42FBE1802FD541
sha3_384: b1ac45c1cebdb5ae1fedb045222427a240f5ac119f2143b67a77c99c06b18c69bbe6b41855fc5606add9e90552c17bbe
ep_bytes: d2483cf18221b87687c0b1e79582d95d
timestamp: 1971-05-16 00:00:00

Version Info:

0: [No Data]

Lazy.449442 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.449442
SkyhighBehavesLike.Win32.Generic.dc
McAfeeTrojan-FVOQ!DADD4DE8E062
MalwarebytesCrypt.Trojan.MSIL.DDS
VIPREGen:Variant.Lazy.449442
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
K7GWTrojan ( 005a45ef1 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Lazy.D6DBA2
BitDefenderThetaGen:NN.ZexaF.36608.n8W@a83RoFe
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik_AGen.BGU
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Glupteba-10016954-0
KasperskyVHO:Trojan.Win32.Copak.gen
BitDefenderGen:Variant.Lazy.449442
NANO-AntivirusTrojan.Win32.Kryptik.fjoxxc
AvastWin32:Evo-gen [Trj]
EmsisoftGen:Variant.Lazy.449442 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.dadd4de8e0624ef2
SophosMal/Inject-GJ
IkarusTrojan.Win32.Glupteba
JiangminTrojan.Copak.cxtx
VaristW32/Trojan.NJGF-3047
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.Kryptik.girh
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
MicrosoftTrojan:Win32/Glupteba.MT!MTB
ZoneAlarmVHO:Trojan.Win32.Copak.gen
GDataWin32.Trojan.PSE.11XGYE9
GoogleDetected
AhnLab-V3Packed/Win.FJB.C5537712
Acronissuspicious
VBA32Trojan.Khalesi
ALYacGen:Variant.Lazy.449442
TACHYONTrojan/W32.Selfmod
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.BF57 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.30d18f
DeepInstinctMALICIOUS

How to remove Lazy.449442?

Lazy.449442 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment