Malware

What is “Win32:LimeRAT-A [Trj]”?

Malware Removal

The Win32:LimeRAT-A [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:LimeRAT-A [Trj] virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Win32:LimeRAT-A [Trj]?


File Info:

name: 582E6E5DE0EB20060EF0.mlw
path: /opt/CAPEv2/storage/binaries/5995ca5b9dd3bd1d52a42bc72673d8574fe10e26af1865469afb70263f4e1e2b
crc32: BC55CA16
md5: 582e6e5de0eb20060ef0f7da05d770bf
sha1: 10de74b69395a572ca58a90f95eea934d076a58d
sha256: 5995ca5b9dd3bd1d52a42bc72673d8574fe10e26af1865469afb70263f4e1e2b
sha512: 40aa79cbe6ea26e1883b03ac5ba6f373b55ac9e2d2ebc21ab494a87da77331374e93c87799c6f1e1f964ffac23b6b37936dea9db47c8d29fe2173d6212fbe6c5
ssdeep: 6144:7LBBdKVnX5wcbgjzaxKgslupXO5SCnud:7SXOxjzmxKoX+nud
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D2442734F3E76466D35B0A37D491357446BAAD136A03F22A089EF2B49D32FC5CE42876
sha3_384: cd285f67ce5bab7614195195bbbddc072e90b5c45dc4dbcfd98f864f432ac5c654159cebb82d608e8d706127b581b43f
ep_bytes: ff250020400000000000000000000000
timestamp: 2053-01-05 23:35:12

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName: Google LLC
FileDescription: Google Installer
FileVersion: 1.3.36.101
InternalName: Google Update
LegalCopyright: Copyright 2018 Google LLC
LegalTrademarks:
OriginalFilename: Google Update
ProductName: Google Update
ProductVersion: 1.3.36.101
Assembly Version: 1.3.36.101

Win32:LimeRAT-A [Trj] also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanIL:Trojan.MSILZilla.2050
FireEyeGeneric.mg.582e6e5de0eb2006
ALYacIL:Trojan.MSILZilla.2050
CylanceUnsafe
ZillyaTrojan.Agent.Win32.2589830
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00550dd41 )
AlibabaTrojan:Win32/AsyncRat.23172a5d
K7GWTrojan ( 00550dd41 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Trojan.YZTY-2565
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Agent.CAK
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Razy-9790647-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderIL:Trojan.MSILZilla.2050
AvastWin32:LimeRAT-A [Trj]
TencentMsil.Trojan.Msilzilla.Suoc
Ad-AwareIL:Trojan.MSILZilla.2050
SophosMal/Generic-S
DrWebTrojan.ClipBankerNET.7
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DJ221
McAfee-GW-EditionRDN/Generic.hbg
EmsisoftIL:Trojan.MSILZilla.2050 (B)
SentinelOneStatic AI – Malicious PE
GDataIL:Trojan.MSILZilla.2050
AviraHEUR/AGEN.1203070
GridinsoftRansom.Win32.Miner.sa
ViRobotTrojan.Win32.Z.Limerat.266752
MicrosoftTrojan:Win32/AsyncRat.PA!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.RL_Agent.C3453963
McAfeeRDN/Generic.hbg
MAXmalware (ai score=82)
VBA32TScope.Trojan.MSIL
MalwarebytesBackdoor.LimeRat
TrendMicro-HouseCallTROJ_GEN.R002C0DJ221
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:RjbmJ/rWxxj4lVCJ7RezIQ)
YandexTrojan.Agent!LtZ5C9QYtJA
IkarusTrojan-Spy.Agent
FortinetMSIL/CoinMiner.CFQ!tr
BitDefenderThetaGen:NN.ZemsilF.34212.qm0@aOmKj3h
AVGWin32:LimeRAT-A [Trj]
Cybereasonmalicious.69395a
PandaTrj/GdSda.A

How to remove Win32:LimeRAT-A [Trj]?

Win32:LimeRAT-A [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment