Malware

What is “PWS:Win32/Lmir.AAA”?

Malware Removal

The PWS:Win32/Lmir.AAA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Lmir.AAA virus can do?

  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Anomalous binary characteristics

Related domains:

abc.d1kf.com

How to determine PWS:Win32/Lmir.AAA?


File Info:

crc32: E2361401
md5: 9ff21c41048b3534b31202bb5ba5bbe0
name: kdscan.exe
sha1: c16720beeb126af8f6c8264cff854c5d1ed6263f
sha256: 4f918540a31e102a44a9c7f2345176a70107156d530f12aaaa19ea1c28008df6
sha512: d00bf635eeb4e56361138581efc9e934dc8a2288d044cebe4ac6f933d423e73a189efbc9f7fb6a17cd11b3838531afa0b01e1e5323acbb2bb502ddeb940874b1
ssdeep: 98304:A+Dw2Nh8Ko696MyymRusVyXWm0gpa7P55+t39bPBGl2gfl7pQKKg:A+nNKKoJMORuPps6tNbkAgFQpg
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: x7b2cx4e00x5ba2x670dxff08www.d1kf.comxff09
FileVersion: 116.0.0.0
CompanyName: x7b2cx4e00x5ba2x670d
Comments: x6279x91cfx67e5x8be2x3001x7ba1x7406x5febx9012x7684x7535x5546/x5faex5546x8f85x52a9x8f6fx4ef6
ProductName: x5febx9012x6279x91cfx67e5x8be2x9ad8x624b
ProductVersion: 116.0.0.0
FileDescription: x6279x91cfx67e5x8be2x3001x7ba1x7406x5febx9012x7684x8f6fx4ef6
Translation: 0x0804 0x04b0

PWS:Win32/Lmir.AAA also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanGen:Variant.Strictor.192725
FireEyeGeneric.mg.9ff21c41048b3534
CAT-QuickHealTrojan.GenericRI.S12398784
McAfeeArtemis!9FF21C41048B
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabRiskware.Win32.Strictor.1!c
BitDefenderGen:Variant.Strictor.192725
K7GWAdware ( 0050718d1 )
Cybereasonmalicious.1048b3
F-ProtW32/Trojan.CLL.gen!Eldorado
APEXMalicious
AvastWin32:Malware-gen
GDataGen:Variant.Strictor.192725
Endgamemalicious (moderate confidence)
SophosGeneric PUA MB (PUA)
ComodoMalware@#2pahlesgg2o22
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Flyagent.rc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Strictor.192725 (B)
CyrenW32/Trojan.CLL.gen!Eldorado
MAXmalware (ai score=89)
Antiy-AVLGrayWare/Win32.FlyStudio.a
ArcabitTrojan.Strictor.D2F0D5
MicrosoftPWS:Win32/Lmir.AAA
AhnLab-V3Malware/Win32.Generic.C2176068
Acronissuspicious
VBA32BScope.Trojan.KillFiles
ALYacGen:Variant.Strictor.192725
Ad-AwareGen:Variant.Strictor.192725
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R01FH0CD820
RisingMalware.Lmir!8.E96A (CLOUD)
SentinelOneDFI – Malicious PE
eGambitHackTool.Generic
FortinetW32/QQWare.A!tr
BitDefenderThetaGen:NN.ZexaF.34106.@pKfaCBuk6nb
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)

How to remove PWS:Win32/Lmir.AAA?

PWS:Win32/Lmir.AAA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment