Malware

Lazy.59449 removal tips

Malware Removal

The Lazy.59449 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.59449 virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • .NET file is packed/obfuscated with SmartAssembly
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Lazy.59449?


File Info:

name: 7FAC1255CA03E2370B85.mlw
path: /opt/CAPEv2/storage/binaries/30443b172cf76708f7ffbd282d11ab0d2ad35b3fa37e10bce5efa65bdfb4e4d9
crc32: 196216FD
md5: 7fac1255ca03e2370b85bec3636f6a61
sha1: 293ac74f7c641508538d763d16959860a9fee319
sha256: 30443b172cf76708f7ffbd282d11ab0d2ad35b3fa37e10bce5efa65bdfb4e4d9
sha512: a56aab9718f29bf8f012a3b78ae804455ec8a76d91225793ddfd9fa0420bac9f8bbee5cf8e4b2cb293725969d770c3b46c8f5da93b2b21987c5ae7d40b9fd2e5
ssdeep: 1536:Dz7MLbnaJ5FzHgFf+62UyFh6cvH01Yh6w06C:DzanaPGfqUyH6ccSh6w06C
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1D2535B08BF8DDA13C95A8BBD94E1625507F3EC726B43EBC76D4431F92D627A05803A87
sha3_384: cc3a1616d9d329f68cc9b0d30e436abfdb5c4e34fef589d77f89bf5f04088968fbdf02f3af89963083eb914e799ce05f
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-11-28 21:22:32

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: InsuranceBotConsole.exe
LegalCopyright:
OriginalFilename: InsuranceBotConsole.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Lazy.59449 also known as:

LionicTrojan.Win32.Lazy.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.7fac1255ca03e237
ALYacGen:Variant.Lazy.59449
SymantecML.Attribute.HighConfidence
APEXMalicious
BitDefenderGen:Variant.Lazy.59449
MicroWorld-eScanGen:Variant.Lazy.59449
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Lazy.59449
EmsisoftGen:Variant.Lazy.59449 (B)
McAfee-GW-EditionRDN/Generic.dx
GDataGen:Variant.Lazy.59449
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Lazy.DE839
MicrosoftProgram:Win32/Uwamson.A!ml
AhnLab-V3Malware/Win.Generic.C4818044
McAfeeRDN/Generic.dx
MAXmalware (ai score=88)
TrendMicro-HouseCallTROJ_GEN.R002H06L221
SentinelOneStatic AI – Suspicious PE
FortinetPossibleThreat
AVGWin32:Malware-gen
Cybereasonmalicious.f7c641

How to remove Lazy.59449?

Lazy.59449 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment