Malware

Win32/Packed.Asprotect.LP (file analysis)

Malware Removal

The Win32/Packed.Asprotect.LP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.Asprotect.LP virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Created a process from a suspicious location

How to determine Win32/Packed.Asprotect.LP?


File Info:

name: 3EC9C222E3AA1C02E93A.mlw
path: /opt/CAPEv2/storage/binaries/ed93ba155f594b0f00b170b397d2b0a89f81c68aa65215a0baec0e832f1996cc
crc32: D8FF579F
md5: 3ec9c222e3aa1c02e93a94758810479b
sha1: d7280beb96276ce398c1765ca1a1287c133290ce
sha256: ed93ba155f594b0f00b170b397d2b0a89f81c68aa65215a0baec0e832f1996cc
sha512: 2d2c2688d8b165a3aa1d164d6f962d3ecb4f24b21e7acb0aaccd623013eb7e411d15c4521afa6b9bec0dd2887586db8fed0b2bbea006468e5ac9a645810b126a
ssdeep: 98304:kcW+4VKaLIt7uc/zanF1MXU2Bi93VsvHqjxpgXA:DZ4VKa07t/zEF1Mk+sUKvgXA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AB16331BA2918E71FD927A3388163763676A6D30065C5A3773C83C3FD1B009CA66DB67
sha3_384: c9175e9caf7ece03d12579d3994dce0300b31882e1485bb8f7993e8cc1c1a85d46f3a4cbe3ed555987c5717cdc73519f
ep_bytes: e85a040000e98efeffff3b0d68d64300
timestamp: 2019-12-05 07:37:23

Version Info:

0: [No Data]

Win32/Packed.Asprotect.LP also known as:

LionicTrojan.Win32.Stealer.i!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.48269612
FireEyeGeneric.mg.3ec9c222e3aa1c02
CAT-QuickHealTrojanSpy.Stealer
ALYacTrojan.GenericKD.48269612
CylanceUnsafe
SangforInfostealer.Win32.Stealer.gen
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/ASProtect.H.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Packed.Asprotect.LP
APEXMalicious
Paloaltogeneric.ml
KasperskyUDS:Trojan-PSW.Win32.Stealer.gen
BitDefenderTrojan.GenericKD.48269612
AvastWin32:Malware-gen
TencentWin32.Packed.Asprotect.Losf
Ad-AwareTrojan.GenericKD.48269612
SophosMal/Generic-S
DrWebTrojan.Siggen16.39600
TrendMicroTROJ_GEN.R002C0PBB22
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
EmsisoftTrojan.GenericKD.48269612 (B)
SentinelOneStatic AI – Malicious SFX
GDataTrojan.GenericKD.48269612
AviraTR/Redcap.qmxvl
Antiy-AVLTrojan/Generic.ASMalwS.352145A
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R311737
McAfeeArtemis!3EC9C222E3AA
MAXmalware (ai score=87)
VBA32BScope.Trojan.Tiggre
MalwarebytesTrojan.MalPack
RisingSpyware.Raccoon!8.1235D (CLOUD)
IkarusTrojan.Win32.ASProtect
FortinetW32/PossibleThreat
BitDefenderThetaGen:NN.ZexaF.34232.K7YaaCpt@Rpk
AVGWin32:Malware-gen
PandaTrj/CI.A

How to remove Win32/Packed.Asprotect.LP?

Win32/Packed.Asprotect.LP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment