Malware

How to remove “PWS:Win32/Lmir.BMQ”?

Malware Removal

The PWS:Win32/Lmir.BMQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Lmir.BMQ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial binary language: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine PWS:Win32/Lmir.BMQ?


File Info:

crc32: 8059DCA8
md5: 4f348dcb1a19a093034b128f1437b973
name: 4F348DCB1A19A093034B128F1437B973.mlw
sha1: 1a141cf85f39b8a73d858b22ad9f745cda66a850
sha256: 5e44de2b6cefc38410a81bd0e8b9b20c8258291c8734be5b7ce85d3e4bf526bc
sha512: 6e972c33a57be37febbb9f1f440c0af24e0ca70e740e74c36c49c2d2a956c0d7265f5d717106548a8448b212283a3efa87a61f80b83b0b22264d9171fe9a451c
ssdeep: 24576:Nak/7Nk4RZywilDKHxoa0ahm+3qMOA/6GsBGUNNqVjk07z8oDqE:Nak/YZKHn0amXAJsBLNNWg07Io+E
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709 (C) 2010
InternalName: LoginTools.exe
FileVersion: 1,0,0,0
CompanyName: 178x7f51x6e38x5de5x4f5cx5ba4
ProductName: x5546x4e1ax7a0bx5e8f
ProductVersion: 1, 0, 0, 0
FileDescription: x5546x4e1ax7a0bx5e8f
OriginalFilename: LoginTools.exe
Translation: 0x0804 0x03a8

PWS:Win32/Lmir.BMQ also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.134753
FireEyeGeneric.mg.4f348dcb1a19a093
Qihoo-360Generic/Trojan.156
McAfeeGenericRXAA-FA!4F348DCB1A19
CylanceUnsafe
SangforMalware
BitDefenderGen:Variant.Bulz.134753
K7GWRiskware ( 005439d61 )
K7AntiVirusRiskware ( 005439d61 )
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
AlibabaTrojanPSW:Win32/ManBat.d952171b
NANO-AntivirusTrojan.Win32.GameTool.iiraep
AegisLabTrojan.Win32.Bulz.4!c
TencentMalware.Win32.Gencirc.10ce0c5c
Ad-AwareGen:Variant.Bulz.134753
EmsisoftGen:Variant.Bulz.134753 (B)
F-SecureHeuristic.HEUR/AGEN.1103850
DrWebTrojan.DownLoader35.4463
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R067C0DAS21
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SophosMal/Generic-S
IkarusTrojan.ManBat
AviraHEUR/AGEN.1103850
MAXmalware (ai score=81)
Antiy-AVLTrojan[PSW]/Win32.Lmir
MicrosoftPWS:Win32/Lmir.BMQ
GridinsoftTrojan.Win32.Downloader.oa
ArcabitTrojan.Bulz.D20E61
GDataGen:Variant.Bulz.134753
CynetMalicious (score: 85)
AhnLab-V3Malware/Win32.RL_Generic.R329115
BitDefenderThetaGen:NN.ZelphiF.34804.qT0ba4XgWvdi
ALYacGen:Variant.Bulz.134753
VBA32Trojan.SDP.27105
MalwarebytesRiskWare.GameTool
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/RiskWare.GameTool.S
TrendMicro-HouseCallTROJ_GEN.R067C0DAS21
RisingMalware.Lmir!8.E96A (CLOUD)
YandexRiskWare.GameTool!pMU37xFVQRE
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/Fugrafa.7364!tr
AVGWin32:Malware-gen
Cybereasonmalicious.b1a19a
MaxSecureTrojan.Malware.109381195.susgen

How to remove PWS:Win32/Lmir.BMQ?

PWS:Win32/Lmir.BMQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment