Rootkit

Rootkit.Win32.Lapka.an information

Malware Removal

The Rootkit.Win32.Lapka.an is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Rootkit.Win32.Lapka.an virus can do?

  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Rootkit.Win32.Lapka.an?


File Info:

name: 04D7F6B83127351394A9.mlw
path: /opt/CAPEv2/storage/binaries/f936e66f9f512b3b08a3ec27787a7c6c206ac4953c30ad5c7c0c81ef86e5cf61
crc32: B7A71BDC
md5: 04d7f6b83127351394a9b18a76cc410c
sha1: ff2cafb5da17ab9003779382af9dc38b742ca403
sha256: f936e66f9f512b3b08a3ec27787a7c6c206ac4953c30ad5c7c0c81ef86e5cf61
sha512: 220a391a6f7e7809aa01a6a5d53ae926ea54081d893d00ca505dd71df4996aae897a1cf393164b591a8c8300bc5b9ce46ee6398b97d90173b0580b7a6661c0d7
ssdeep: 768:GgYj3IrmOOGqhRT4JXbgQ6Fl4CFgHdXn3dqxlZlQ53qZ3n7OkASLTq29MWUH+Nkz:/YErGGWhyyKVHb33qVn7OkAcTq2fOTFF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EF23F11DC208B42FF60B607EAD27CF2B5549C94D11589B0F5C69E39E60B1E4A7EA780F
sha3_384: bbe739466f791825b967da93b324e3f836978844550570885e19a4db30b5932459676face95851ba5ee5f0046f861a73
ep_bytes: 60be00a040008dbe0070ffff5783cdff
timestamp: 2006-12-25 17:45:31

Version Info:

0: [No Data]

Rootkit.Win32.Lapka.an also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Heur.Mint.Zard.30
FireEyeGeneric.mg.04d7f6b831273513
CAT-QuickHealTrojan.Nitol.A
MalwarebytesGeneric.Malware.AI.DDS
ZillyaRootkit.Lapka.Win32.344
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0052a8cd1 )
K7AntiVirusTrojan ( 0052a8cd1 )
BitDefenderThetaAI:Packer.7A731A971F
CyrenW32/Nitol.R.gen!Eldorado
SymantecW32.Virut.CF
Elasticmalicious (moderate confidence)
ESET-NOD32Win32/Virut.NBP
APEXMalicious
ClamAVWin.Malware.Nitol-9953104-0
KasperskyRootkit.Win32.Lapka.an
BitDefenderGen:Heur.Mint.Zard.30
NANO-AntivirusTrojan.Win32.Gamania.dbovay
ViRobotBackdoor.Win32.ServStart.Gen.A
AvastWin32:Agent-AXZD [Trj]
TencentTrojan.Win32.Lapka.bw
SophosMal/Behav-004
BaiduWin32.Virus.Virut.gen
F-SecureTrojan.TR/Staser.apzjs
DrWebTrojan.PWS.Gamania.44384
VIPREGen:Heur.Mint.Zard.30
McAfee-GW-EditionBehavesLike.Win32.Suspicious.pc
Trapminemalicious.high.ml.score
EmsisoftGen:Heur.Mint.Zard.30 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Worm.ServStart.B
JiangminWin32/Virut.bv
GoogleDetected
AviraTR/Staser.apzjs
Antiy-AVLVirus/Win32.Virut.ce
XcitiumTrojWare.Win32.ServStart.bre@6az8zh
ArcabitTrojan.Mint.Zard.30
SUPERAntiSpywareTrojan.Agent/Gen-ServStart
ZoneAlarmRootkit.Win32.Lapka.an
MicrosoftDDoS:Win32/Nitol.A
CynetMalicious (score: 100)
AhnLab-V3Dropper/Win32.Dinwod.R105213
McAfeeArtemis!04D7F6B83127
MAXmalware (ai score=83)
VBA32BScope.TrojanDDoS.Macri
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_NITOL.SMN1
RisingTrojan.DDOS!1.AF40 (CLASSIC)
IkarusDDoS.Win32.Nitol
FortinetW32/ServStart.GL!tr
AVGWin32:Agent-AXZD [Trj]
DeepInstinctMALICIOUS

How to remove Rootkit.Win32.Lapka.an?

Rootkit.Win32.Lapka.an removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment