Malware

Win32/Injector.YPO information

Malware Removal

The Win32/Injector.YPO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.YPO virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Injector.YPO?


File Info:

name: CF3EFD7FE6A75D891E6D.mlw
path: /opt/CAPEv2/storage/binaries/6480c6c5104d5258fe753237cd4be8d05931aeac2e539c1ccfd2418af9170b62
crc32: DFFAAED6
md5: cf3efd7fe6a75d891e6d2a1a90ecf3b0
sha1: d998f382947cdc4cd2b374574f6f35cdcad38898
sha256: 6480c6c5104d5258fe753237cd4be8d05931aeac2e539c1ccfd2418af9170b62
sha512: 5e3b488b5b9d62b8d2c00d6a172cbd1152c3462ad73719ec56595bb616938ac4eaf6cced2f514ee348b8388cc79ec6464cd3f3786fbddcdaaf2dca67ca8f4b2b
ssdeep: 1536:FgsSROC13SOCrbGT5rLL6i4aE9iUOi2nUQPwx:i3wOCrST51oiUOPUQPwx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12E938D13B9D1C575F3A10ABCE8109464F4B7FE7209255BD7A3A80F884D6A2817CDA38F
sha3_384: 047aa927ac30803edbd227f48436a5b85a8cf51591d5bcef51588dcf196799e12ba1bc63fd89dd80e3d3258f6c6b1bdd
ep_bytes: 558bec83c4f053b8b4874000e84fc0ff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32/Injector.YPO also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Andromeda.a!c
MicroWorld-eScanGen:Variant.Delf.118
FireEyeGeneric.mg.cf3efd7fe6a75d89
SkyhighPWS-Zbot.gen.aow
McAfeePWS-Zbot.gen.aow
Cylanceunsafe
ZillyaDownloader.Andromeda.Win32.241
SangforVirus.Win32.Cryptor.atdI
K7AntiVirusTrojan ( 0040f2c31 )
BitDefenderGen:Variant.Delf.118
K7GWTrojan ( 0040f2c31 )
Cybereasonmalicious.2947cd
ArcabitTrojan.Delf.118
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.YPO
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Downloader.Andromeda-27
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Injector.64984da6
NANO-AntivirusTrojan.Win32.Tobfy.bbsnmj
ViRobotTrojan.Win32.A.Downloader.89600.CV
TencentWin32.Trojan.Generic.Qgil
EmsisoftGen:Variant.Delf.118 (B)
F-SecureTrojan.TR/Dldr.Andromeda.B
DrWebBackDoor.Andromeda.22
VIPREGen:Variant.Delf.118
TrendMicroTSPY_ZBOT.SM16
Trapminemalicious.moderate.ml.score
SophosMal/EncPk-AGD
SentinelOneStatic AI – Suspicious PE
JiangminTrojanDownloader.Andromeda.xf
WebrootW32.Malware.Gen
AviraTR/Dldr.Andromeda.B
MAXmalware (ai score=100)
Antiy-AVLTrojan[Downloader]/Win32.Kuluoz
KingsoftWin32.HeurC.KVMH008.a
XcitiumSuspicious@#1b8jzzz3wrus9
MicrosoftWorm:Win32/Gamarue.I
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Delf.118
GoogleDetected
BitDefenderThetaGen:NN.ZelphiF.36744.fGW@aqdrQmd
ALYacGen:Variant.Delf.118
DeepInstinctMALICIOUS
VBA32Malware-Cryptor.Inject.gen
PandaTrj/Velphi.b
ZonerTrojan.Win32.10933
TrendMicro-HouseCallTSPY_ZBOT.SM16
RisingWorm.Gamarue!8.13B (CLOUD)
YandexTrojan.Injector!QBVWnfVWbTE
IkarusTrojan-Dropper.Win32.Dapato
FortinetW32/Injector.WCT!tr
AVGWin32:Cryptor
AvastWin32:Cryptor
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Win32/Injector.YPO?

Win32/Injector.YPO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment