Malware

What is “PWS:Win32/Lmir.O”?

Malware Removal

The PWS:Win32/Lmir.O is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Lmir.O virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Checks for the presence of known windows from debuggers and forensic tools
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara detections observed in process dumps, payloads or dropped files

How to determine PWS:Win32/Lmir.O?


File Info:

name: D5A588D74E9FCA84F20F.mlw
path: /opt/CAPEv2/storage/binaries/51acb24a4de415f8b7e10d2aba3bcc0db7dcd2717852df741f060eea828f2754
crc32: 8D6F0EE9
md5: d5a588d74e9fca84f20f9022b6830332
sha1: a73f0eaa175022b6e53feb07d1b8f05bc50b2d26
sha256: 51acb24a4de415f8b7e10d2aba3bcc0db7dcd2717852df741f060eea828f2754
sha512: 2bdec445932e42d8e30d61320b0c4e1e56d9e03d982b6b8457a8c593df6d7abd125d36c8a20a1d24875a4ea2ab8c3222e7102a0e5e82bffcfe76642930c4ca01
ssdeep: 768:nekUKO6OhIAzVJHrLT/fQ6q2a10F9ZLzfnUhZ8cj8YudBAPHInKKVF:TUKAiAVJHrLT/fLU98TM6KK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12E438E875B5AD8F3C2E50ABD31E626034FB6BE300EAA48C7DBFBA6C566704474924507
sha3_384: e9ee5b11162e030c9e7189c5e62b0e8304623005d4daeea4168fb160dc618148e73172a296103c03ad585668ba359ee3
ep_bytes: 558bec6aff68d020400068801a400064
timestamp: 2008-09-02 11:38:03

Version Info:

0: [No Data]

PWS:Win32/Lmir.O also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.kZcP
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.PWS.OnlineGames.ZWU
ClamAVWin.Spyware.52254-2
FireEyeGeneric.mg.d5a588d74e9fca84
CAT-QuickHealTrojanpws.Lmir.27096
SkyhighBehavesLike.Win32.Generic.qt
McAfeegeneric!bg.ffl
MalwarebytesMachineLearning/Anomalous.100%
ZillyaTrojan.OnLineGames.Win32.93907
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanPSW:Win32/OnLineGames.34106716
K7GWTrojan ( 004bcce41 )
K7AntiVirusTrojan ( 004bcce41 )
BitDefenderThetaGen:NN.ZexaF.36744.dqX@aCIgQHnb
SymantecInfostealer
ESET-NOD32a variant of Win32/PSW.OnLineGames.NXI
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-GameThief.Win32.OnLineGames.tgph
BitDefenderTrojan.PWS.OnlineGames.ZWU
NANO-AntivirusTrojan.Win32.OnLineGames.bxotz
AvastWin32:Susn-K [Trj]
TencentMalware.Win32.Gencirc.14012fb3
EmsisoftTrojan.PWS.OnlineGames.ZWU (B)
BaiduWin32.Trojan-PSW.OLGames.by
F-SecureTrojan.TR/Spy.Gen
DrWebTrojan.MulDrop4.226
VIPRETrojan.PWS.OnlineGames.ZWU
TrendMicroMal_OLGM-15
Trapminemalicious.high.ml.score
SophosMal/Zhengtu-A
SentinelOneStatic AI – Malicious PE
GDataTrojan.PWS.OnlineGames.ZWU
JiangminTrojanSpy.OnLineGames.bvw
WebrootW32.Malware.Gen
GoogleDetected
AviraTR/Spy.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan[GameThief]/Win32.OnLineGames
KingsoftWin32.Troj.OnLineGamesT.ba.61440
XcitiumTrojWare.Win32.PSW.OnlineGames.~AXZ@18ktm
ArcabitTrojan.PWS.OnlineGames.ZWU
ZoneAlarmTrojan-GameThief.Win32.OnLineGames.tgph
MicrosoftPWS:Win32/Lmir.O
VaristW32/OnlineGames.AS.gen!Eldorado
Acronissuspicious
VBA32BScope.TrojanSpy.Treemz
ALYacTrojan.PWS.OnlineGames.ZWU
Cylanceunsafe
PandaTrj/Lineage.JPT
TrendMicro-HouseCallMal_OLGM-15
RisingTrojan.PSW.Win32.GameOL.peb (CLASSIC)
YandexTrojan.PWS.OnLineGames!uKq4lswOwOI
IkarusTrojan.Agent
MaxSecureTrojan.Malware.1136865.susgen
FortinetW32/Dropper.GE!tr
AVGWin32:Susn-K [Trj]
Cybereasonmalicious.a17502
DeepInstinctMALICIOUS

How to remove PWS:Win32/Lmir.O?

PWS:Win32/Lmir.O removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment