Trojan

Trojan.LameShield removal tips

Malware Removal

The Trojan.LameShield is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.LameShield virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (12 unique times)
  • Starts servers listening on 127.0.0.1:0
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Greek
  • The binary likely contains encrypted or compressed data.
  • Exhibits behavior characteristic of Kelihos malware
  • Installs itself for autorun at Windows startup
  • Collects information about installed applications
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests credentials from local FTP client softwares
  • Installs WinPCAP
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.LameShield?


File Info:

crc32: F1CF3944
md5: 1c837a8f652c36ea8d85f5ffee70068e
name: file_4571518150a8181b403df4ae7ad54ce8b16ded0c.exe
sha1: 4571518150a8181b403df4ae7ad54ce8b16ded0c
sha256: 426511145595346a6aee1d3483685ad32674f626a4695bb91aa82c1b016a0f1c
sha512: 6bd1b460b6d8f4f1782a60f0215a4b07569489bf6ef4685d1d3d9144c3fbea0879ac6d364a3d71a143caf31228ea8c65726c89fbcddc6803d59fec4133428b7d
ssdeep: 12288:tgnqyfy1FHvnnzVg4ARZNN7iEcRHgsB8OfEWFB76NTmHf0ALSEWt:ynF6nn5jARZNsEAAwl3j2BmZpWt
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.LameShield also known as:

BkavW32.OnGamesLT270912LJHY.Trojan
MicroWorld-eScanTrojan.VIZ.Gen.1
FireEyeGeneric.mg.1c837a8f652c36ea
CAT-QuickHealFraudTool.Security
ALYacTrojan.VIZ.Gen.1
CylanceUnsafe
VIPRETrojan.Win32.Winwebsec.fd (v)
SangforMalware
K7AntiVirusTrojan ( 0040797b1 )
BitDefenderTrojan.VIZ.Gen.1
K7GWTrojan ( 0040797b1 )
Cybereasonmalicious.f652c3
TrendMicroBKDR_KELIHOS.SI
BaiduWin32.Trojan.Kryptik.wc
F-ProtW32/SuspPack.EX.gen!Eldorado
SymantecSecShieldFraud!gen9
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Agent-1773675
GDataTrojan.VIZ.Gen.1
KasperskyBackdoor.Win32.Bredolab.abmn
AlibabaBackdoor:Win32/Bredolab.88dbf2f7
NANO-AntivirusTrojan.Win32.Bredolab.fetflb
ViRobotBackdoor.Win32.A.Bredolab.873472
AegisLabTrojan.Win32.Bredolab.4!c
RisingBackdoor.Bredolab!8.CC (CLOUD)
Ad-AwareTrojan.VIZ.Gen.1
EmsisoftTrojan.VIZ.Gen.1 (B)
ComodoTrojWare.Win32.Kryptik.AMAE@4qxt5z
F-SecureTrojan.TR/Autorun.HH
DrWebTrojan.Fakealert.33824
ZillyaTrojan.FakeAV.Win32.224386
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Trojan.cc
MaxSecureTrojan.Malware.4566699.susgen
Trapminemalicious.high.ml.score
CMCBackdoor.Win32.Bredolab!O
SophosTroj/FakeAV-FWY
IkarusTrojan-PSW.Win32.Tepfer
CyrenW32/SuspPack.EX.gen!Eldorado
JiangminBackdoor/Bredolab.ouq
WebrootW32.Malware.Gen
AviraTR/Autorun.HH
MAXmalware (ai score=100)
Antiy-AVLTrojan[Backdoor]/Win32.Bredolab
Endgamemalicious (high confidence)
ArcabitTrojan.VIZ.Gen.1
ZoneAlarmBackdoor.Win32.Bredolab.abmn
MicrosoftBackdoor:Win32/Kelihos.F
AhnLab-V3Trojan/Win32.Tepfer.R37144
Acronissuspicious
McAfeeFakeAV-SecurityTool.mw
TACHYONTrojan/W32.Relhis.873472.H
VBA32TScope.Malware-Cryptor.SB
MalwarebytesTrojan.LameShield
PandaGeneric Malware
ESET-NOD32a variant of Win32/Kryptik.AMAE
TrendMicro-HouseCallBKDR_KELIHOS.SI
TencentWin32.Backdoor.Bredolab.Eanr
YandexBackdoor.Bredolab!IAGx5tq4u+4
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.AGAI!tr
BitDefenderThetaGen:NN.ZexaF.34090.1qW@aO@KLpmG
AVGWin32:MalOb-KQ [Cryp]
AvastWin32:MalOb-KQ [Cryp]
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360HEUR/Malware.QVM20.Gen

How to remove Trojan.LameShield?

Trojan.LameShield removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment