Trojan

Trojan.Heur3.LPT.mnGfaKArD!dib removal tips

Malware Removal

The Trojan.Heur3.LPT.mnGfaKArD!dib is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur3.LPT.mnGfaKArD!dib virus can do?

  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Heur3.LPT.mnGfaKArD!dib?


File Info:

name: 40FA349BD531C57AC317.mlw
path: /opt/CAPEv2/storage/binaries/1cfc45039a481c5f08565385940faa1bf725bef854860f8202e2cd756a239b55
crc32: FB8892C7
md5: 40fa349bd531c57ac317ee08b0d66694
sha1: 62766ad6d900391096ed93c7d162b5cecaac776f
sha256: 1cfc45039a481c5f08565385940faa1bf725bef854860f8202e2cd756a239b55
sha512: 41c8756971cff6324d52ab5b766fd390082d36f4bdeb87079dca376913d6c74fbf3cff948e427c7ffd0428ffe31ace9b5e826a02a8f62c27d89546fe40371a26
ssdeep: 24576:8lywWTt+FbRW80muUbkFXkF8DcRYiFATHocUSLTA55ifeD72H:06QhR6EAFFDKYrTcSLTAjU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14145235A7520DC81DA3EA3716D8BC165A6773C6BED095EA27ACDB3CD1033C6BA113027
sha3_384: e37cb24a6124f6975c4b6bc43dcf34162ba13e5b45e69521365c0446a053bbbd03d5d0db0ac8276b000ec60f779243b4
ep_bytes: 60be00704a008dbe00a0f5ff5789e58d
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan.Heur3.LPT.mnGfaKArD!dib also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Inject.1b!c
AVGWin32:Malware-gen
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Trojan.Heur3.LPT.mnGfaKArD!dib
FireEyeGeneric.mg.40fa349bd531c57a
McAfeeArtemis!40FA349BD531
MalwarebytesMalware.Heuristic.1003
VIPREGen:Trojan.Heur3.LPT.mnGfaKArD!dib
SangforTrojan.Win32.Kryptik.Vomv
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/GenKryptik.a5105e13
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.bd531c
CyrenW32/ABRisk.FBME-0668
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/GenKryptik.GEGT
CynetMalicious (score: 100)
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Inject.aooto
BitDefenderGen:Trojan.Heur3.LPT.mnGfaKArD!dib
AvastWin32:Malware-gen
TencentWin32.Trojan.Inject.Xmhl
EmsisoftGen:Trojan.Heur3.LPT.mnGfaKArD!dib (B)
F-SecureDropper.DR/Delphi.Gen
ZillyaTrojan.GenKryptik.Win32.162474
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.Krypt
WebrootW32.Trojan.Heur3.LPT.mnGfaKArD
AviraDR/Delphi.Gen
Antiy-AVLTrojan/Win32.GenKryptik
ArcabitTrojan.Heur3.LPT.mnGfaKArD!dib
ZoneAlarmTrojan.Win32.Inject.aooto
GDataGen:Trojan.Heur3.LPT.mnGfaKArD!dib
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C5344755
BitDefenderThetaAI:Packer.385A4BD521
ALYacGen:Trojan.Heur3.LPT.mnGfaKArD!dib
MAXmalware (ai score=87)
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002H07LR22
RisingBackdoor.XRat!8.44C7 (C64:YzY0OrpcqE4fMSwc)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.11926561.susgen
FortinetW32/GenKryptik.GEGT!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Trojan.Heur3.LPT.mnGfaKArD!dib?

Trojan.Heur3.LPT.mnGfaKArD!dib removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment