lmc.exe

LAN Messenger

The executable lmc.exe has been detected as malware by 2 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘LAN Messenger’.
Publisher:
LAN Messenger

Product:
LAN Messenger

Version:
1.2.35

MD5:
0b54a243d376cf4bef41c9c193d3136c

SHA-1:
7befe3b351c0d8926e4824963b176aabbb1b781e

SHA-256:
1a4c46b3c2e5e6fdb68f9dc36eaa926055e4798fd1b0be17dad3af647cc66b78

Scanner detections:
2 / 68

Status:
Malware

Analysis date:
4/28/2024 11:39:42 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Floxif.H virus
6.3.12010.0

F-Prot
W32/Floxif.B
4.6.5.141

File size:
1.7 MB (1,799,623 bytes)

Product version:
1.2.35

Copyright:
Copyright © 2010-2012 Qualia Digital Solutions.

Original file name:
lmc.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\lan messenger\lmc.exe

File PE Metadata
Compilation timestamp:
7/25/2012 2:13:34 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.56

Entry address:
0x12A0

Entry point:
E9, B8, E1, 03, 00, 08, C7, 04, 24, 02, 00, 00, 00, FF, 15, 60, D6, 57, 00, E8, 98, FE, FF, FF, 90, 8D, B4, 26, 00, 00, 00, 00, 55, 8B, 0D, 78, D6, 57, 00, 89, E5, 5D, FF, E1, 8D, 74, 26, 00, 55, 8B, 0D, 6C, D6, 57, 00, 89, E5, 5D, FF, E1, 90, 90, 90, 90, 55, 89, E5, 83, EC, 18, C7, 04, 24, 00, 20, 53, 00, E8, 4E, 60, 0E, 00, 52, 85, C0, 74, 65, C7, 44, 24, 04, 13, 20, 53, 00, 89, 04, 24, E8, 41, 60, 0E, 00, 83, EC, 08, 85, C0, 74, 11, C7, 44, 24, 04, 08, F0, 56, 00, C7, 04, 24, 00, 89, 55, 00, FF, D0, 8B...
 
[+]

Entropy:
6.5940

Packer / compiler:
SecureEXE, 0x3.0

Code size:
1.2 MB (1,225,216 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
LAN Messenger

Command:
C:\Program Files\lan messenger\lmc.exe


Remove lmc.exe - Powered by Reason Core Security