Malware

SScope.Downware.LMN information

Malware Removal

The SScope.Downware.LMN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What SScope.Downware.LMN virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Unconventionial language used in binary resources: Russian
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

forces.procoldpro.ru

How to determine SScope.Downware.LMN?


File Info:

crc32: 008C875D
md5: a840d2d88abffa5d217bd248218b1f89
name: A840D2D88ABFFA5D217BD248218B1F89.mlw
sha1: 4410e3105ade411707fc588cb806ff8e4fa6191a
sha256: 474961fed2b45480372359797f311a61d01c5438e6542af564a27130dec19963
sha512: 365250ff76a77159ca0526a824bacbfaf2fa850b410d7fb556ae83a12489663f6015edac113e08692e4ae29dde151e2b7cf605043da481b04656b92628c084b8
ssdeep: 12288:E0MtmzeS7DSocydZLmziFrlxsVm46mBd8KezyjjCvpO1Z3rL8:CmzeS7DSocydZLqiFrX46mP8KeGjjGY
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

SScope.Downware.LMN also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.787373
FireEyeGeneric.mg.a840d2d88abffa5d
CAT-QuickHealPUA.Oooitservi.Gen
Qihoo-360HEUR/QVM19.1.5625.Malware.Gen
ALYacGen:Variant.Razy.787373
CylanceUnsafe
VIPRETrojan.Win32.Generic.pak!cobra
SangforMalware
K7AntiVirusUnwanted-Program ( 0040f9cf1 )
BitDefenderGen:Variant.Razy.787373
K7GWAdware ( 004b31441 )
Cybereasonmalicious.88abff
BaiduWin32.Adware.Kryptik.e
CyrenW32/Ogimant.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Kasperskynot-a-virus:Downloader.Win32.LMN.agj
NANO-AntivirusTrojan.Win32.LMN.dvtool
RisingMalware.Undefined!8.C (TFE:1:P32b5WzFKoJ)
Ad-AwareGen:Variant.Razy.787373
ComodoMalCrypt.Indus!@1qrzi1
F-SecurePotentialRisk.PUA/LoadMoney.qoabn
DrWebTrojan.LoadMoney.451
ZillyaAdware.1ClickDownloadCRT.Win32.966
InvinceaGeneric ML PUA (PUA)
McAfee-GW-EditionLoadMoney
EmsisoftApplication.InstallMon (A)
IkarusVirus.Win32.Cryptor
JiangminTrojanDropper.Agent.bril
WebrootPua.Adware.Gen
AviraPUA/LoadMoney.qoabn
MAXmalware (ai score=87)
Antiy-AVLTrojan[Downloader:not-a-virus]/Win32.LMN.agj
MicrosoftSoftwareBundler:Win32/Ogimant
GridinsoftTrojan.LoadMoney.sd!c
ArcabitTrojan.Razy.DC03AD
ZoneAlarmnot-a-virus:Downloader.Win32.LMN.agj
GDataGen:Variant.Razy.787373
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.LoadMoney.R137742
Acronissuspicious
McAfeeLoadMoney
VBA32SScope.Downware.LMN
MalwarebytesPUP.Optional.LoadMoney
ESET-NOD32a variant of Win32/Adware.LoadMoney.AFA
TencentMalware.Win32.Gencirc.10c77a22
SentinelOneStatic AI – Malicious PE
eGambitPE.Heur.InvalidSig
FortinetRiskware/DownloadLMN
BitDefenderThetaGen:NN.ZexaF.34634.ImX@ayLp9cek
AVGWin32:AdwareSig [Adw]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove SScope.Downware.LMN?

SScope.Downware.LMN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment