Malware

Win32/Injector.LPY removal

Malware Removal

The Win32/Injector.LPY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.LPY virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Mimics the system’s user agent string for its own requests
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process created a hidden window
  • Unconventionial language used in binary resources: Korean
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Behavior consistent with a dropper attempting to download the next stage.
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Win32/Injector.LPY?


File Info:

crc32: 6B12368A
md5: dd38535a6e603c1cc59365496da466c4
name: DD38535A6E603C1CC59365496DA466C4.mlw
sha1: 2bc7efbb969d30a72fe7005920a60ef2073dba8c
sha256: 522060a789411152b8a38a30d861a96ee42e7cb7ecc8fdc17ffa9fd966266bd6
sha512: 5f53dfb0088031a608147e4866cb3af0856b4df5d914f85827b9411a063ce3c5737a940b980a7de069c1ef0d7a817f525d5afe07e2b2f75765c10988fe51b7fb
ssdeep: 1536:5dtAmhPFmhv0QVXzhLnR0hc2UF3irOWjgscdOQ7n122hLzQ2mUjRxzmOZW:DamFkJR0C2wShjxcoq122hzQ0RmOZ
type: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed

Version Info:

LegalCopyright: Copyright (C) 2009 Bitsum Technologies and Jeremy Collake
InternalName: PETrim
FileVersion: 2, 9, 9, 0
CompanyName: Bitsum Technologies
ProductName: PETrim Application
ProductVersion: 2, 9, 9, 0
FileDescription: PETrim
OriginalFilename: PETrim.exe
Translation: 0x0409 0x04b0

Win32/Injector.LPY also known as:

BkavW32.AIDetect.malware1
DrWebTrojan.MulDrop3.24037
CynetMalicious (score: 100)
CylanceUnsafe
ZillyaDropper.VB.Win32.38254
SangforSuspicious.Win32.Dreidel.gi0awKBHh9ei
CrowdStrikewin/malicious_confidence_60% (D)
Cybereasonmalicious.b969d3
CyrenW32/Trojan.NIRG-9107
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.LPY
APEXMalicious
TotalDefenseWin32/Ransom.GBD
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.iug
NANO-AntivirusTrojan.Win32.Blocker.bdpxix
TencentWin32.Trojan.Blocker.Wsjw
SophosMal/Generic-S
ComodoMalware@#3sqbhogflyhlt
BitDefenderThetaGen:NN.ZexaF.34628.gi0aaKBHh9ei
VIPRELooksLike.Win32.Malware!vb (v)
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.dd38535a6e603c1c
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Blocker.pnf
AviraTR/LockScreen.32165
MicrosoftTrojan:Win32/Vigorf.A
AhnLab-V3Trojan/Win32.Bifrose.C110110
McAfeeArtemis!DD38535A6E60
VBA32TrojanRansom.Blocker
MalwarebytesMalware.Heuristic.1001
PandaTrj/CI.A
RisingRansom.Blocker!8.12A (CLOUD)
YandexTrojan.DR.VB!3gfF5qAeToA
IkarusTrojan.Win32.Spyeye
FortinetW32/Refroso.DZP!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HxEAzHIA

How to remove Win32/Injector.LPY?

Win32/Injector.LPY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment