Trojan

About “Trojan-GameThief.Win32.Lmir.oa” infection

Malware Removal

The Trojan-GameThief.Win32.Lmir.oa is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-GameThief.Win32.Lmir.oa virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Manipulates data from or to the Recycle Bin
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Trojan-GameThief.Win32.Lmir.oa?


File Info:

name: 8F0AD33ED4AEE31D477D.mlw
path: /opt/CAPEv2/storage/binaries/e2bf2e969ee09c5b9a4eea61c983807d9b1e7703654f86589d42e9f51653a305
crc32: 6781D04F
md5: 8f0ad33ed4aee31d477da6839e99e074
sha1: 5729fdc4d2d32b6d751e10725db5c4982d1f0636
sha256: e2bf2e969ee09c5b9a4eea61c983807d9b1e7703654f86589d42e9f51653a305
sha512: a2764f27ac6b49001356e054e01bc908aa8e5d4fe99896263ce22e29bb37b1ae8625c2766b6e4bed5c2793a79042877c9eb18df35d98f7f41d47c5769b5fc642
ssdeep: 49152:I2oj4GuGlWC3YlQt8CWVQ7VFGogWAcF8jH7VaOtXc3:I2ouQ3YI+g
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T101C55B1BA1AD82E8C0BAD178C6178D07FBB1381D4334A6EB06E156961F17AF1DE3E711
sha3_384: 5254d870abbf83b8b133ecad6ce86e78b72413ba58f48160a2bd4ed55fd16b59a4d368d5312c5054ab9b016d58ca7440
ep_bytes: 60be00a042008dbe0070fdffc78708d7
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan-GameThief.Win32.Lmir.oa also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (moderate confidence)
DrWebTrojan.Siggen3.61405
MicroWorld-eScanTrojan.Agent.CGVL
FireEyeGeneric.mg.8f0ad33ed4aee31d
CAT-QuickHealTrojan.GenericIH.S24070444
McAfeePWS-CangKu
MalwarebytesMalware.AI.2382208213
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaAI:Packer.EF4FD6EE1F
CyrenW32/Legendmir.XJFG-4309
SymantecW32.HLLP.Philis
tehtrisGeneric.Malware
ESET-NOD32Win32/PSW.Legendmir.OA
TrendMicro-HouseCallPE_LEGMIR.B
ClamAVWin.Trojan.Lmir-24
KasperskyTrojan-GameThief.Win32.Lmir.oa
BitDefenderTrojan.Agent.CGVL
NANO-AntivirusTrojan.Win32.Lmir.dxaowj
AvastWin32:Delf-AFC [Trj]
TencentVirus.Win32.Syphilis.a
Ad-AwareTrojan.Agent.CGVL
SophosML/PE-A + W32/LegMir-BM
ComodoTrojWare.Win32.PSW.Legendmir.OA@2lge
BaiduWin32.Trojan-PSW.OLGames.be
ZillyaTrojan.Lmir.Win32.762
TrendMicroPE_LEGMIR.B
McAfee-GW-EditionBehavesLike.Win32.Autorun.vh
EmsisoftTrojan.Agent.CGVL (B)
IkarusTrojan-PWS.Win32.Lmir.mw
JiangminTrojan.PSW.LMir.ec
ViRobotTrojan.Win32.PSWLmir.84992.B
ZoneAlarmTrojan-GameThief.Win32.Lmir.oa
GDataTrojan.Agent.CGVL
TACHYONVirus/W32.Philis
AhnLab-V3Win32/Lemir.212992
Acronissuspicious
VBA32Trojan.Sabsik.FL
ALYacTrojan.Agent.CGVL
MAXmalware (ai score=88)
APEXMalicious
RisingVirus.Syphilis!1.9BE9 (CLASSIC)
YandexTrojan.GenAsa!l4kdDOnxqiQ
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan-GameThief.Lmir.OA
FortinetW32/Lmir.7128!tr
AVGWin32:Delf-AFC [Trj]
Cybereasonmalicious.ed4aee
PandaW32/Legmir.J

How to remove Trojan-GameThief.Win32.Lmir.oa?

Trojan-GameThief.Win32.Lmir.oa removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment