Malware

W32/LegMir-BM information

Malware Removal

The W32/LegMir-BM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What W32/LegMir-BM virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Manipulates data from or to the Recycle Bin
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Deletes executed files from disk

How to determine W32/LegMir-BM?


File Info:

name: A3518E565F0EAD8DF648.mlw
path: /opt/CAPEv2/storage/binaries/175d5ef83d4e9c24b4b6f4944f08b322ef9e5a6c4c8e681789fd5336d085bf15
crc32: 5A6F7C52
md5: a3518e565f0ead8df64823584d303f15
sha1: f02da32e63298fc3842440894ab506ec7ea50e50
sha256: 175d5ef83d4e9c24b4b6f4944f08b322ef9e5a6c4c8e681789fd5336d085bf15
sha512: 1fcf591f812d281eb6c9122402c3d850e495d1d3cd60fba5f0170b440b44c6f224a3a82e6b1d3b8682f86357a6c19f52e7441953bcc96fd165842b8cc303a6d7
ssdeep: 3072:h0v4Yb2eruGgAaeXWhTj+fWYA9Y2ibyZdI4CC2AXxrciu1BHTOSPg:Wvrb22uGLbWhTjYWbcyT55K9Pg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10514AF5FD38250ECC527C2B486AA6772B935FC660B21377F376CE2702F51DA46A2A710
sha3_384: bc1a7168ef251054f5749e51a68e177741593c08f0e7c29eaab1c62d3de719d7ff30869f57b33772b6f00257b9cab18e
ep_bytes: 60be00a042008dbe0070fdffc78708d7
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

W32/LegMir-BM also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (moderate confidence)
DrWebTrojan.Siggen3.61405
MicroWorld-eScanTrojan.Agent.CGVL
FireEyeGeneric.mg.a3518e565f0ead8d
CAT-QuickHealTrojan.GenericIH.S24070444
McAfeePWS-CangKu
CylanceUnsafe
VIPRETrojan.Agent.CGVL
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.65f0ea
BitDefenderThetaAI:Packer.A91EC2291F
CyrenW32/Legendmir.JCFQ-5826
SymantecW32.HLLP.Philis
ESET-NOD32a variant of Win32/Delf.NBN
TrendMicro-HouseCallPE_LEGMIR.B
ClamAVWin.Trojan.Lmir-24
KasperskyTrojan-GameThief.Win32.Lmir.oa
BitDefenderTrojan.Agent.CGVL
NANO-AntivirusTrojan.Win32.Lmir.dxaowj
AvastWin32:Delf-AFC [Trj]
TencentVirus.Win32.Syphilis.a
Ad-AwareTrojan.Agent.CGVL
EmsisoftTrojan.Agent.CGVL (B)
ComodoTrojWare.Win32.PSW.Legendmir.OA@3b0u
BaiduWin32.Trojan-PSW.OLGames.be
TrendMicroPE_LEGMIR.B
McAfee-GW-EditionBehavesLike.Win32.Autorun.cc
Trapminemalicious.moderate.ml.score
SophosW32/LegMir-BM
IkarusTrojan-PWS.Win32.Lmir.mw
GDataWin32.Trojan.PSE1.12DYCUZ
JiangminTrojan.PSW.LMir.ec
AviraW32/PSW.Lmir.oa
MAXmalware (ai score=89)
Antiy-AVLTrojan/Generic.ASBOL.C631
ArcabitTrojan.Agent.CGVL
ViRobotTrojan.Win32.PSWLmir.84992.B
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
CynetMalicious (score: 100)
AhnLab-V3Win32/Lemir.212992
Acronissuspicious
VBA32Trojan.Sabsik.FL
ALYacTrojan.Agent.CGVL
TACHYONVirus/W32.Philis
MalwarebytesMalware.AI.2382208213
APEXMalicious
RisingVirus.Syphilis!1.9BE9 (CLASSIC)
YandexTrojan.GenAsa!l4kdDOnxqiQ
SentinelOneStatic AI – Malicious PE
FortinetW32/Lmir.7128!tr
AVGWin32:Delf-AFC [Trj]
PandaW32/Legmir.J
CrowdStrikewin/malicious_confidence_70% (D)

How to remove W32/LegMir-BM?

W32/LegMir-BM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment