Threat Database Trojans Trojan.Lamer.BK

Trojan.Lamer.BK

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 5,954
Threat Level: 80 % (High)
Infected Computers: 1,016
First Seen: January 24, 2023
Last Seen: July 19, 2026
OS(es) Affected: Windows

Your system has been detected to have a threat identified as Trojan.Lamer.BK. This detection indicates that your computer is infected with a type of malicious software that can potentially harm your system and compromise your personal data. It is essential to take immediate action to remove this threat and prevent any further damage.

What Is Trojan.Lamer.BK?

Trojan.Lamer.BK is a type of Trojan, which is a broad category of malware that can perform various malicious activities on an infected system. Trojans are often disguised as legitimate software, but they can cause significant harm by stealing sensitive information, installing additional malware, or providing unauthorized access to your system. The name "Trojan.Lamer.BK" suggests that it may be a variant of a known Trojan, but without more specific information, it's difficult to determine its exact nature or origin.

How Trojan.Lamer.BK Operates

Trojans like Trojan.Lamer.BK typically operate by exploiting vulnerabilities in software or tricking users into installing them. Once installed, they can run in the background, hiding from the user and avoiding detection by security software. They can communicate with their creators or other malicious servers, sending sensitive information or receiving instructions to perform specific tasks. Trojans can also install additional malware, such as spyware, adware, or ransomware, which can further compromise the system.

Symptoms of Infection

The symptoms of a Trojan.Lamer.BK infection can vary, but common signs include slow system performance, unexpected pop-ups or advertisements, and unfamiliar programs or icons on your desktop. You may also notice that your browser is being redirected to suspicious websites or that your search results are being hijacked. In some cases, you may not notice any symptoms at all, which is why regular scans with reputable security software are essential for detecting and removing threats like Trojan.Lamer.BK.

  • Unexplained changes to your system settings or configuration
  • Unexpected crashes or freezes
  • New, unfamiliar icons or programs on your desktop
  • Slow system performance or lag
  • Unwanted pop-ups or advertisements

How to Remove Trojan.Lamer.BK

  1. Restart your system in Safe Mode with Networking to prevent the malware from running and to allow your security software to operate more effectively.
  2. Use a reputable malware removal tool, such as SpyHunter, to perform a full scan of your system and detect any malicious files or programs.
  3. Uninstall any suspicious programs or applications that you don't recognize or that were installed without your knowledge or consent.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and run another scan with your security software to ensure that the threat has been completely removed.

Conclusion

Removing Trojan.Lamer.BK from your system requires careful attention and a thorough approach. By following the steps outlined above and using reputable security software, you can help protect your system and prevent further damage. It's essential to remain vigilant and take proactive measures to prevent future infections, such as keeping your operating system and software up to date, using strong antivirus software, and avoiding suspicious downloads or links. By taking these steps, you can help keep your system safe and secure.

Analysis Report

General information

Family Name: Trojan.Lamer.BK
Signature status: Root Not Trusted

Known Samples

MD5: 1b20af49df6ef9bebb9325b2ae574f56
SHA1: 417a1eb20a66ee75c43bba471dc3a7f4562b5b59
File Size: 3.05 MB, 3045968 bytes
MD5: 445836526c19ff02db7cf6fa876e24a8
SHA1: 63434bc05c61f679770034f16fe7cb3270c7edcd
SHA256: 2D7DE0FA5EBB1F2D2C2F0CC6898BA8A7CADA1AC7A2608C502F6A5DAB196FA1A3
File Size: 1.48 MB, 1475944 bytes
MD5: a8a7d1eb767181be3e010337dc590719
SHA1: df60b3510e9b7fec215a60f171cbbb20945efe48
SHA256: C7E9A524C2D9841A8549A1495CBD7D9C762BF29FBB809FAECE7495D356B4EB70
File Size: 343.46 KB, 343464 bytes
MD5: bc7e28b01dc3d3a061118adbce53b57d
SHA1: 69476c82cb53cdd63129a091ae161607e225ad93
SHA256: 81299F1AFDD0EDE27880402E0E68FA4C383D5C81B51F3D48E7BA5D9358DFAB61
File Size: 403.58 KB, 403576 bytes
MD5: 64ca2a4c7dbf60abfd6454e260d5cd62
SHA1: 46b97de0eda7dd839a3efe7f763ccdaa7c3a09b7
SHA256: FB98FA8B12E48D0082761231285D8569B87AD150B29EA1077C90B299A964F7D7
File Size: 319.08 KB, 319080 bytes
Show More
MD5: 594d2424edf58333e1731069376f378d
SHA1: d85e902631745e0b1ba28da783c7dd95a91f6fd2
SHA256: CB754F7DD97555B13A16DD9A24A3A3E5E8D186729C4F16480893F5E12B28662E
File Size: 869.20 KB, 869198 bytes
MD5: d573281473213a347e9cb49f14dde105
SHA1: 63c6dcd61a0a68e8e03dfeaaa289b3d5c0a7a508
SHA256: 2118191B4D49D8D75BD0B6AA64CE072AB29A04B19C32822073D7C3C98927990A
File Size: 312.31 KB, 312312 bytes
MD5: 535b565e1f764be60b5f4825d8105eb8
SHA1: 6751078320b2464b05010eb8cb0c4ef033f1744a
SHA256: 271567EE5A7EDD5AC8F057136B9253EC389D010A623D552E7088087A98F5B5AF
File Size: 1.62 MB, 1619816 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 4.5.0.0
  • 3.2.3886.32527
  • 1.0.0.0
Comments
  • Server Manager of WKFramework
  • SQL Scripter - Data scripting and report utility
  • This installation was built with Inno Setup.
Company Name
  • IT Works Corporation
  • RevolutionarySoftware.Com
  • WKI - OA Sistemi Software Factory
File Description
  • Auction Bargain Detector Setup
  • Ez OFF Setup
  • GSX Resigner1
  • manage
  • POLK
  • PTXDIT
  • ServerManager assembly
  • SQL Scripter
File Version
  • 4.7.6
  • 4.5.0.0
  • 3.2.3886.32527
  • 1.0.0.2
  • 1.0.0.0
Internal Name
  • GSX Resigner1.exe
  • manage.exe
  • POLK.exe
  • PTXDIT.exe
  • ServerManager.exe
  • SQL-Scripter.exe
Legal Copyright
  • Copyright © 2009
  • Copyright © 2012
  • IT Works Corporation
  • OA Sistemi
  • RevolutionarySoftware.Com
Original Filename
  • GSX Resigner1.exe
  • manage.exe
  • POLK.exe
  • PTXDIT.exe
  • ServerManager.exe
  • SQL-Scripter.exe
Product Name
  • Ez OFF
  • GSX Resigner1
  • manage
  • POLK
  • PTXDIT
  • SQL Scripter
Product Version
  • 4.7.6
  • 4.5.0.0
  • 3.2.3886.32527
  • 1.0.0.0

Digital Signatures

Signer Root Status
IT Works Corporation Thawte Premium Server CA Root Not Trusted

File Traits

  • big overlay
  • x86

Block Information

Total Blocks: 829
Potentially Malicious Blocks: 17
Whitelisted Blocks: 812
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 x 0 0 x 0 x 0 x 0 0 x x 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Banload.X

Files Modified

File Attributes
c:\programdata\microsoft\crypto\rsa\machinekeys\089189092c9af742ea27309b63e81914_bfeb5820-9643-42ad-a79f-071dff4d8e64 Generic Write,Read Attributes
c:\programdata\microsoft\crypto\rsa\machinekeys\430edff4da1fcf44075861fb343574e9_bfeb5820-9643-42ad-a79f-071dff4d8e64 Generic Write,Read Attributes
c:\programdata\microsoft\crypto\rsa\machinekeys\439e44c5159355cb4d4aaacff8b6b8b4_bfeb5820-9643-42ad-a79f-071dff4d8e64 Generic Write,Read Attributes
c:\programdata\microsoft\crypto\rsa\machinekeys\8b9129f8b77b4cc88386f1deea5e4ddc_bfeb5820-9643-42ad-a79f-071dff4d8e64 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-re2o4.tmp\417a1eb20a66ee75c43bba471dc3a7f4562b5b59_0003045968.tmp Generic Write,Read Attributes
c:\users\user\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-3119368278-1123331430-659265220-1001 Generic Write,Read Attributes
c:\users\user\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-3119368278-1123331430-659265220-1001\2876f66e7f9858baac7d57556c530d03_bfeb5820-9643-42ad-a79f-071dff4d8e64 Generic Write,Read Attributes
c:\users\user\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-3119368278-1123331430-659265220-1001\3ae51ddf87e3defd986804f81b82abe1_bfeb5820-9643-42ad-a79f-071dff4d8e64 Generic Write,Read Attributes
c:\users\user\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-3119368278-1123331430-659265220-1001\3f5e6051489dcbb8507d848a49bf60f1_bfeb5820-9643-42ad-a79f-071dff4d8e64 Generic Write,Read Attributes
c:\users\user\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-3119368278-1123331430-659265220-1001\5dfaf7ad38ddfcf8f9819de9d126bbbc_bfeb5820-9643-42ad-a79f-071dff4d8e64 Generic Write,Read Attributes
Show More
c:\users\user\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-3119368278-1123331430-659265220-1001\94801a8f9984241bf84b3ba118583248_bfeb5820-9643-42ad-a79f-071dff4d8e64 Generic Write,Read Attributes
c:\users\user\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-3119368278-1123331430-659265220-1001\9d674e63a6319e2841c7a250ae6bcae6_bfeb5820-9643-42ad-a79f-071dff4d8e64 Generic Write,Read Attributes
c:\users\user\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-3119368278-1123331430-659265220-1001\9d674e63a6319e2841c7a250ae6bcae6_bfeb5820-9643-42ad-a79f-071dff4d8e64_deleted_ Generic Write,Read Attributes
c:\users\user\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-3119368278-1123331430-659265220-1001\9d674e63a6319e2841c7a250ae6bcae6_bfeb5820-9643-42ad-a79f-071dff4d8e64_deleted__deleted_ Generic Write,Read Attributes
c:\users\user\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-3119368278-1123331430-659265220-1001\9d674e63a6319e2841c7a250ae6bcae6_bfeb5820-9643-42ad-a79f-071dff4d8e64_deleted__deleted__deleted_ Generic Write,Read Attributes
c:\users\user\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-3119368278-1123331430-659265220-1001\9d674e63a6319e2841c7a250ae6bcae6_bfeb5820-9643-42ad-a79f-071dff4d8e64_deleted__deleted__deleted__deleted_ Generic Write,Read Attributes
c:\users\user\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-3119368278-1123331430-659265220-1001\aee3d74ab4db95f68827c3e43fe5c3ab_bfeb5820-9643-42ad-a79f-071dff4d8e64 Generic Write,Read Attributes
c:\users\user\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-3119368278-1123331430-659265220-1001\c1fbd70d44cf2ffa6b1a8701c2afadd3_bfeb5820-9643-42ad-a79f-071dff4d8e64 Generic Write,Read Attributes
c:\users\user\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-3119368278-1123331430-659265220-1001\d585eefb9ccb99e73aebcefbc8891a9b_bfeb5820-9643-42ad-a79f-071dff4d8e64 Generic Write,Read Attributes
c:\users\user\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-3119368278-1123331430-659265220-1001\d5e75450ec360c01655d20bd6563e7a4_bfeb5820-9643-42ad-a79f-071dff4d8e64 Generic Write,Read Attributes
c:\users\user\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-3119368278-1123331430-659265220-1001\ee64dde0cb12eea52def8094878a50ca_bfeb5820-9643-42ad-a79f-071dff4d8e64 Generic Write,Read Attributes
c:\users\user\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-3119368278-1123331430-659265220-1001\f2f21a618891abf0cb9e019cd85e606d_bfeb5820-9643-42ad-a79f-071dff4d8e64 Generic Write,Read Attributes
c:\users\user\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-3119368278-1123331430-659265220-1001\f3908a4f38af90ca6a12fff0dbaac1a6_bfeb5820-9643-42ad-a79f-071dff4d8e64 Generic Write,Read Attributes
c:\users\user\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-3119368278-1123331430-659265220-1001\f54951b4fc460ed17c1e642b65a349d6_bfeb5820-9643-42ad-a79f-071dff4d8e64 Generic Write,Read Attributes
c:\windows\appcompat\programs\amcache.hve Read Data,Read Control,Write Data
c:\windows\appcompat\programs\amcache.hve.log1 Read Data,Write Data
c:\windows\appcompat\programs\amcache.hve.log2 Read Data,Write Data
c:\windows\assembly Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �l�8�tX�jg�8 �� �v xy ����T��������%���5��Bx��!wz#��$kF%:�&� &�-(�(X�(�)�`*J*9*�"-!R/9�0P%1`1�1HO5,]>3�@V�B��G�IH[uH�pJ��K��N$N�U_*V �X�.X�\teb"hc�wg�Xh�r RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Process Shell Execute
  • CreateProcess
User Data Access
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext

Shell Command Execution

"C:\Users\Vpxakttt\AppData\Local\Temp\is-RE2O4.tmp\417a1eb20a66ee75c43bba471dc3a7f4562b5b59_0003045968.tmp" /SL5="$30276,2683923,75776,c:\users\user\downloads\417a1eb20a66ee75c43bba471dc3a7f4562b5b59_0003045968.exe"
C:\Windows\Microsoft.NET\Framework\v2.0.50727\\dw20.exe dw20.exe -x -s 1124

Trending

Most Viewed

Loading...