Home / Spyware Encyclopedia / Proxy.Lamb << Back

Recommendation to Automatically remove Proxy.Lamb


Our products can remove Proxy.Lamb and thousands of other Virus and Spyware automatically and instantly.

Proxy.Lamb Details


  • Category Proxy
  • Discovered 5/13/2009 11:35:00 AM
  • Modified 7/6/2020 2:38:47 PM
  • Threat Level High
  • Category Description
    Proxy Trojan turns the victim's computer into a proxy server. This gives the attacker the opportunity to do everything from your computer, including the possibility of conducting credit card fraud and other illegal activities, or even to use system to launch malicious attacks against other networks.

The following Files were created:
VALUEFILESIZECOMPANYNAMEVERSIONSIGNATUREDate
sysmodule64.dll 67072  dd87c93365c5340093d75b213217a4b1 
sysmodule32.dll 50688  7c4fb87e528c6283729265fb40d92f58 
sysmodule32.dll 50176  708becfd4c850c3e28e2586a6b9475e8 
Trojan-PSW.Win32.Lmir.s.dll 5313  46cc6b71ebf1ef2519356b30bf87aa6f 
Trojan-PSW.Win32.Lmir.sa.exe 37052  336aa8925d63ae38457e91d7434a95d7 
Trojan-PSW.Win32.Lmir.sm.exe 38588  1f90a5e9d4e1d6264f681f997e648efb 
cqdll.dll 55296  03f1307f984ee5897e7b1359932ea6aa 
TROJAN-PSW.WIN32.LMIR.SB.dll 5632  76fb67747a3509975f8335dffedf9da4 
cqdll.dll 30720  9602f7ce8cc7c9f76af42125464d7f47 
cqdll.dll 56320  ad7107b25dc890033f93216e63792cf9 

The following Registry Entries were created:
..\Software\Microsoft\Windows\CurrentVersion\Run\\"internot.EXE"\"internot.EXE"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"a_rundlla.3"\"%WIN.SYS32%\TROJAN-PSW.WIN32.LMIR.SA.exe"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"Ntech.patchs"\"%WIN.SYS32%\TROJAN-PSW.WIN32.LMIR.SM.exe"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"Microsoft windows"\"%WIN%\systemwin.exe"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"Microsoft Windows32"\"%WIN%\system32win.exe"
..\Software\Microsoft\Windows\CurrentVersion\Run\\"Microsoft Internet"\"%WIN%\Internet.exe"
..\Software\Classes\SysModule64.classname\(Default)
..\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\"{081FE200-A103-11D7-A46D-C770E4459F2F}"\"hookmir"
..\Software\Classes\Clsid\{081FE200-A103-11D7-A46D-C770E4459F2F}\(Default)

Notice
Please note that the following information is not controlled or endorsed by Max Secure Software. They are captured automatically by tools in our malware Research Lab as a result of executing Spyware Files or browsing Internet in virtual environment. Please contact us if you find any information inappropriate for removal. All the work contained in this report is copyrighted and should not be copied without permission from Max Secure Antivirus. We do not recommend browsing or removing these entries on your own manually. We do not take any warranty against the use or result of the use of this information.

Home / Malware Encyclopedia << Back

Max Total Security can detect & quarantine this Malware