Trojan

Trojan:Win32/Lazy.AB!MTB removal guide

Malware Removal

The Trojan:Win32/Lazy.AB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Lazy.AB!MTB virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Anomalous binary characteristics

How to determine Trojan:Win32/Lazy.AB!MTB?


File Info:

name: 6BF53AA12F00B23C668C.mlw
path: /opt/CAPEv2/storage/binaries/5333a91eb80440c94361cf87824a05859a18c53d58d8c7f71309d394112e96cf
crc32: 02F35FBC
md5: 6bf53aa12f00b23c668c6d30f3e1f421
sha1: 87be5ee03ca8170eb50ca4c4f8208b9e4a9ea86a
sha256: 5333a91eb80440c94361cf87824a05859a18c53d58d8c7f71309d394112e96cf
sha512: c39028d7e3f533290e070f09b1383934493d3b6d055aee5ac885ea5244b8965f46355cf1f34848da4c770a29a4f9c98458fc7892105eb04d11f6b0cda45c33e6
ssdeep: 1536:G1zzy48untU8fOMEI3jyYf6iuOBq1mPK3WWIthoBW:8zltUeOsBnqEMWWItho0
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1EF935C0FB79513F2C2C202F8111B39A3D7A6BF76132543E357981459E7E8BE0C676269
sha3_384: e299481b6fe4b8406747d2612cada2e0731adc29d1df9b1b90f1ec6201aa31b035085cf6dfc08fe5a8913a6812124d1b
ep_bytes: 6800010000680000000068d8e34000e8
timestamp: 2009-12-23 16:06:34

Version Info:

CompanyName: Scanvec
FileVersion: 1,0,0,0
ProductName: Flexisign
ProductVersion: 1.0.0.0
LegalCopyright: www.signs101.com
Translation: 0x0000 0x04e4

Trojan:Win32/Lazy.AB!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.70192763
SkyhighBehavesLike.Win32.Generic.mh
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTool.Agent.Win32.131744
CrowdStrikewin/malicious_confidence_70% (D)
K7GWRiskware ( 00584baa1 )
K7AntiVirusRiskware ( 00584baa1 )
ArcabitTrojan.Generic.D42F0E7B
VirITBackdoor.Win32.Generic.CNLA
SymantecML.Attribute.HighConfidence
ESET-NOD32BAT/Agent.QBP
CynetMalicious (score: 100)
ClamAVWin.Packed.Zpack-10001780-0
KasperskyHoax.Win32.Agent.gen
BitDefenderTrojan.GenericKD.70192763
AvastWin32:Malware-gen
TencentTrojan.Win32.Agentb.fc
EmsisoftTrojan.GenericKD.70192763 (B)
F-SecureBackdoor.BDS/Agent.ytehe
VIPRETrojan.GenericKD.70192763
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.6bf53aa12f00b23c
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Suspicious PE
JiangminTrojanDropper.Daws.fyt
VaristW32/Tiggre.H.gen!Eldorado
AviraBDS/Agent.ytehe
MAXmalware (ai score=87)
Antiy-AVLTrojan[Backdoor]/BAT.Teldoor
MicrosoftTrojan:Win32/Lazy.AB!MTB
ZoneAlarmVHO:Hoax.Win32.Agent.gen
GDataTrojan.GenericKD.70192763
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R620203
ALYacTrojan.GenericKD.70192763
Cylanceunsafe
PandaTrj/Genetic.gen
ZonerTrojan.Win32.64771
RisingPUF.Agent!8.1B6B (TFE:5:GXiPvwgCvOC)
YandexRiskware.Hoax!HihFrko2lhQ
IkarusTrojan.Tiggre
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenericKD.8CE0!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Lazy.AB!MTB?

Trojan:Win32/Lazy.AB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment