Threat Search: 

ThreatExpert's Statistics for Trojan-PWS.Win32.Lmir [Ikarus]:

Trojan-PWS.Win32.Lmir [Ikarus] is also known as:
Threat AliasNumber of Incidents
Win-Trojan/Hupigon.Gen [AhnLab]5
Mal/Generic-A [Sophos]4
Mal/Inject-K, Mal/Behav-024, Mal/Behav-009 [Sophos]3
PWS:Win32/Lmir.BMR [Microsoft]3
PWS-LegMir [McAfee]3
Trojan.Midgare.EYZ [PC Tools]3
TrojanDownloader:Win32/Small.gen!AO [Microsoft]3
W32.SillyFDC [Symantec]3
Worm:Win32/Autorun.DM!dll [Microsoft]3
Downloader [Symantec]2
Downloader.gen.a [McAfee]2
Mal/Behav-010, Mal/GamePSW-B, Mal/Behav-024, Mal/GamePSW-C, Mal/Delf-M, Mal/Behav-027 [Sophos]2
Mal/Behav-327 [Sophos]2
PWS:Win32/Lmir [Microsoft]2
Trojan Horse [Symantec]2
Trojan.DL.Delf.YIC [PC Tools]2
Trojan-Downloader.Win32.Delf.bmc [Kaspersky Lab]2
Trojan-Dropper.Win32.Agent.bamh [Kaspersky Lab]2
Trojan-PSW.Win32.Lmir.gen [Kaspersky Lab]2
W32/Autorun.worm.ff [McAfee]2
Backdoor.Trojan [Symantec]1
Backdoor.Win32.IRCBot.gen [Kaspersky Lab]1
Backdoor:Win32/Poison.Y [Microsoft]1
Downloader-BLE!a [McAfee]1
Dropper/Xema.243253 [AhnLab]1
Generic Malware.eb [McAfee]1
Infostealer [Symantec]1
Infostealer.Hukle [Symantec]1
Infostealer.Lemir.105 [Symantec]1
Infostealer.Lemir.Gen [Symantec]1
Mal/Behav-009 [Sophos]1
Mal/Behav-024, Mal/Behav-009 [Sophos]1
Mal/Behav-024, Mal/Behav-010, Mal/GamePSW-B, Mal/GamePSW-C, Mal/Delf-M, Mal/Behav-027 [Sophos]1
Mal/Behav-024, Mal/Inject-K, Mal/Behav-009 [Sophos]1
Mal/Behav-130 [Sophos]1
Mal/Behav-156, Mal/GamePSW-C [Sophos]1
Mal/DllHook-A [Sophos]1
Mal/EncPk-AO [Sophos]1
Mal/GamePSW-C [Sophos]1
Mal/Gampass-B [Sophos]1
Mal_Legmir2 [Trend Micro]1
PWS:Win32/OnLineGames.BX [Microsoft]1
PWS-LegMir.dll [McAfee]1
PWS-Mmorpg.gen [McAfee]1
Suspicious.MH690 [Symantec]1
Troj/PWS-AWI [Sophos]1
TROJ_AGENT.AHMD [Trend Micro]1
Trojan.Generic [PC Tools]1
Trojan.Win32.Agent.zvr [Kaspersky Lab]1
Trojan.Win32.CDur.bcg [Kaspersky Lab]1
Trojan:Win32/Iniriror.A!dll [Microsoft]1
Trojan:Win32/Meredrop [Microsoft]1
Trojan-Downloader.Win32.Agent.crla [Kaspersky Lab]1
TrojanDownloader:Win32/Tearspear [Microsoft]1
Trojan-Dropper.Win32.Agent.avxb [Kaspersky Lab]1
Trojan-Dropper.Win32.Agent.ayky [Kaspersky Lab]1
Trojan-GameThief.Win32.Lmir.hox [Kaspersky Lab]1
Trojan-GameThief.Win32.OnLineGames.usii [Kaspersky Lab]1
Trojan-GameThief.Win32.OnLineGames.vrbp [Kaspersky Lab]1
Trojan-PSW.Hukle!sd5 [PC Tools]1
Trojan-PSW.Lmir!sd5 [PC Tools]1
Trojan-PSW.Win32.Hukle.t [Kaspersky Lab]1
Trojan-Spy.Win32.Banker.pvr [Kaspersky Lab]1
Trojan-Spy.Win32.Delf.eic [Kaspersky Lab]1
TSPY_LEGMIR.AVQ [Trend Micro]1
W32.SillyIM [Symantec]1
W32.Spybot.Worm [Symantec]1
W32/Rbot-Fam, Mal/Behav-034, Mal/SillyFDC-A, Mal/Behav-010, Mal/TinyDL-T, Mal/Behav-134, Mal/IRCBot-B [Sophos]1
Win-Trojan/OnlineGameHack.165888.V [AhnLab]1
Win-Trojan/OnlineGameHack.61233.K [AhnLab]1
Worm.Win32.AutoRun.aros [Kaspersky Lab]1
Worm:Win32/Pushbot.gen [Microsoft]1
WORM_RBOT.GEN [Trend Micro]1

Trojan-PWS.Win32.Lmir [Ikarus] has the following possible countries of origin:
OriginNumber of Incidents
Brazil4
China3
France1
Russian Federation1

Trojan-PWS.Win32.Lmir [Ikarus] is known to be created as:
%ProgramFiles%\common files\sysanti.exe
%System%\drivers\descvoice.exe
%System%\drivers\etc\4c1044am.dll
%System%\drivers\etc\l4vsapyf.dll
%System%\drivers\etc\th7p5u6t.dll
%System%\iexplore.exe
%System%\interna.dll
%System%\interna.exe
%System%\ls6urnoh.dll
%System%\ro.dll
%System%\svshost.exe
%Temp%\ir_ext_temp_0\autoplay\scripts\prodigy.exe
%Windir%\server.exe
%Windir%\sysmgmt.exe
c:\recycler\services\services.exe
Notes:
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.