Trojan

Trojan:Win32/Lazy.HNA!MTB removal

Malware Removal

The Trojan:Win32/Lazy.HNA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Lazy.HNA!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Lazy.HNA!MTB?


File Info:

name: 4280CD8A348F77BD66C4.mlw
path: /opt/CAPEv2/storage/binaries/3dfc8358b8eb7384740b713d0913e7e4c15c2335824a7dc5eaba573761c231af
crc32: A0DCBD91
md5: 4280cd8a348f77bd66c446b2ff9e3893
sha1: e84711e2ef7bc712517ecc403190c2cf024cc61a
sha256: 3dfc8358b8eb7384740b713d0913e7e4c15c2335824a7dc5eaba573761c231af
sha512: 560c594077bab49a70e6f2e7211fc7e832fc7185380374633965ddf56001afbe61bd31a607a51de5d3fd469cabb42787ee7e02f5454952a4654d3c719b72334e
ssdeep: 768:KTK+ex9NrWZXGFaCj3mgyuxeFQBgAu9GkuvYUAI:Kuv9rWZX9Cj3mgLxwQYAR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10743930263ED4429F2B2D630157693716B367C2A5F7DC34ED7C1D91F2A62E21ABA0723
sha3_384: 1d8ee95347b1d49f4d11bcf3e3a88b9ede8519b8b04bc77f6db287b1a1bc7636d49b22c29c9f9bc81a9960973ea8ee7a
ep_bytes: 81ec00110000be00040001eb00545fb9
timestamp: 2001-08-17 20:54:58

Version Info:

CompanyName: Microsoft Corporation
FileDescription: DrWatson Postmortem Debugger
FileVersion: 5.1.2600.0 (XPClient.010817-1148)
InternalName: drwtsn32.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: drwtsn32.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 5.1.2600.0
Translation: 0x0409 0x04b0

Trojan:Win32/Lazy.HNA!MTB also known as:

BkavW32.AIDetectMalware
AVGWin32:Hematite-C [Inf]
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Hematite.A
FireEyeGeneric.mg.4280cd8a348f77bd
SkyhighArtemis
ALYacWin32.Hematite.A
MalwarebytesVirut.Virus.FileInfector.DDS
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/HWorld.ec364549
BitDefenderThetaGen:NN.ZexaF.36804.dq1@aKmzymni
CynetMalicious (score: 99)
APEXMalicious
ClamAVWin.Virus.Hematite-6232506-0
BitDefenderWin32.Hematite.A
NANO-AntivirusVirus.Win32.Infector.emtrum
AvastWin32:Hematite-C [Inf]
TencentVirus.Win32.Infector.ya
EmsisoftWin32.Hematite.A (B)
F-SecureTrojan.TR/Patched.Gen
VIPREWin32.Hematite.A
Trapminemalicious.moderate.ml.score
SophosW32/HWorld-A
SentinelOneStatic AI – Malicious PE
GDataWin32.Hematite.A
VaristW32/Hematite.A!Generic
AviraTR/Patched.Gen
MAXmalware (ai score=89)
Antiy-AVLGrayWare/Win32.Kryptik.hematite
Kingsoftmalware.kb.a.967
XcitiumVirus.Win32.Hematite.A@77ycil
ArcabitWin32.Hematite.A
MicrosoftTrojan:Win32/Lazy.HNA!MTB
GoogleDetected
McAfeeArtemis!4280CD8A348F
Cylanceunsafe
RisingVirus.Hematite!1.EF53 (CLASSIC)
IkarusTrojan.Agent
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Hematite.A!tr
DeepInstinctMALICIOUS
alibabacloudVirus:Win/HelloWorld.a(dyn)

How to remove Trojan:Win32/Lazy.HNA!MTB?

Trojan:Win32/Lazy.HNA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment