Malware

PWS:Win32/Lmir!B (file analysis)

Malware Removal

The PWS:Win32/Lmir!B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Lmir!B virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine PWS:Win32/Lmir!B?


File Info:

name: 02CA9D4D54A508B344B2.mlw
path: /opt/CAPEv2/storage/binaries/117c9b1ae9d46876ec266636ee2749ef470c6d091fe06b158fa6a949ca0e33d0
crc32: 84D28503
md5: 02ca9d4d54a508b344b2ff5512426603
sha1: b221582b19a28d7ed7f22176711332f77d7accb3
sha256: 117c9b1ae9d46876ec266636ee2749ef470c6d091fe06b158fa6a949ca0e33d0
sha512: 18b82abd1b64963c5452e76db9bc7eb7e48aef968426bf250802a8312ae460d5f4ddef6ad342149a92d990e166fc3ad642e80e72c76ba87dd6be4c7476dcb2ed
ssdeep: 48:azXzjAUlRXbnb6aWN5BMOBjSEsvzdS87+KY5TtYfan8nch2DanfQaEUmHVNI/Lj:szjjbWaWryiJW7+x7wa8cEDafhFm0jj
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1B0C1F63A3FC26EB1E55007B07EA71973BBA2C9B59B4444D787A302E05C62993DE78207
sha3_384: 2d22da7b01e9d2e07420879713281162313232a8670f3a89926036587460043d8ab93a25246f6aa49b6a997bd4a807ac
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2007-02-01 11:22:35

Version Info:

0: [No Data]

PWS:Win32/Lmir!B also known as:

LionicTrojan.Win32.OnLineGames.kYYT
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Malware.!PWS!.FEB11E36
ClamAVWin.Spyware.3654-1
FireEyeGeneric.mg.02ca9d4d54a508b3
SkyhighPWS-LegMir.br.dll
McAfeePWS-LegMir.br.dll
Cylanceunsafe
ZillyaTrojan.OnLineGames.Win32.75020
SangforTrojan.Win32.OnLineGames.PZR
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojanPSW:Win32/OnLineGames.bf2df4d8
K7GWPassword-Stealer ( 004ca6b01 )
K7AntiVirusPassword-Stealer ( 004ca6b01 )
ArcabitGeneric.Malware.!PWS!.FEB11E36
BitDefenderThetaGen:NN.ZedlaF.36680.au4@aeTiG@n
VirITTrojan.Win32.Generic.CMP
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/PSW.OnLineGames.PZR
CynetMalicious (score: 100)
KasperskyTrojan-GameThief.Win32.OnLineGames.xsp
BitDefenderGeneric.Malware.!PWS!.FEB11E36
NANO-AntivirusTrojan.Win32.OnLineGames.ddbckg
AvastWin32:OnLineGames-DD [Trj]
TACHYONTrojan-PWS/W32.WebGame.5632
EmsisoftGeneric.Malware.!PWS!.FEB11E36 (B)
BaiduWin32.Trojan.Agent.fy
F-SecureTrojan-PSW:W32/OnlineGames.gen!H
DrWebTrojan.PWS.Lineage
VIPREGeneric.Malware.!PWS!.FEB11E36
TrendMicroTSPY_ONLINEG.IA
SophosTroj/LegMir-Gen
IkarusTrojan-GameThief.Win32.OnLineGames
JiangminTrojan/PSW.Lineage.ecn
VaristW32/Lineage.1!Generic
AviraTR/Dldr.Delf.alo.3
Antiy-AVLTrojan[GameThief]/Win32.OnLineGames
KingsoftWin32.Troj.Undef.a
XcitiumMalware@#1aowxjnm5wnn
MicrosoftPWS:Win32/Lmir.gen!B
ZoneAlarmTrojan-GameThief.Win32.OnLineGames.xsp
GDataGeneric.Malware.!PWS!.FEB11E36
GoogleDetected
AhnLab-V3Trojan/Win32.OnlineGameHack.R8026
ALYacGeneric.Malware.!PWS!.FEB11E36
MAXmalware (ai score=100)
VBA32MalwareScope.Trojan-PSW.Game.5
PandaTrj/Genetic.gen
TrendMicro-HouseCallTSPY_ONLINEG.IA
RisingStealer.OnlineGames!1.65EC (CLASSIC)
YandexTrojan.DL.OnlineGames.Gen.3
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.1800243.susgen
FortinetW32/Onlinegames.XQB!tr
AVGWin32:OnLineGames-DD [Trj]
DeepInstinctMALICIOUS

How to remove PWS:Win32/Lmir!B?

PWS:Win32/Lmir!B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment