Threat Database Trojans Trojan.LynceBir.A

Trojan.LynceBir.A

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 7,561
Threat Level: 80 % (High)
Infected Computers: 180
First Seen: September 21, 2022
Last Seen: July 27, 2026
OS(es) Affected: Windows

The detection of Trojan.LynceBir.A on your system indicates a potential security threat that requires immediate attention. This report aims to provide you with a comprehensive understanding of the threat, its operational mechanisms, symptoms of infection, and most importantly, guidance on how to remove it from your system.

What Is Trojan.LynceBir.A?

Trojan.LynceBir.A is identified as a Trojan-type threat. Trojans are malicious programs that can sneak onto your computer and perform a variety of harmful actions. They are often disguised as legitimate software, making them difficult to detect. The name "Trojan.LynceBir.A" itself does not specify a known malware family but indicates it is a type of Trojan horse malware, designed to allow unauthorized access to the victim's system.

How Trojan.LynceBir.A Operates

Trojan.LynceBir.A, like other Trojans, operates by deceiving users into installing it on their systems. Once installed, it can create backdoors that allow remote access to the system, potentially leading to data theft, installation of additional malware, or even complete system compromise. Trojans can also be used to disrupt system performance, steal sensitive information, or engage in other malicious activities without the user's knowledge or consent.

Symptoms of Infection

Symptoms of a Trojan infection can vary widely. Common indicators include unusual system behavior, such as unexpected pop-ups, slow system performance, or programs starting and stopping on their own. You might also notice that your system is frequently crashing or that you are being redirected to unwanted websites. Additionally, if you find that your antivirus software is disabled or that you are unable to access certain system settings, it could be a sign of a Trojan infection.

How to Remove Trojan.LynceBir.A

  1. Enter Safe Mode with Networking: This will limit the malware's ability to spread or cause further damage, allowing you to proceed with removal steps more safely.
  2. Conduct a Full Scan with a Reputable Tool: Utilize a trusted anti-malware tool, such as SpyHunter, to perform a full system scan. This can help identify and remove the Trojan and any associated malware.
  3. Uninstall Suspicious Programs: Review your installed programs and uninstall any that you do not recognize or that were installed around the time of the infection.
  4. Reset Your Browser: If your browser (e.g., Chrome, Firefox, Edge) has been affected, resetting it to its default settings can help remove unwanted extensions or settings changes made by the malware.
  5. Reboot and Re-scan: After completing the above steps, reboot your system to ensure all changes take effect, and then perform another scan to verify that the threat has been removed.

Conclusion

Removing Trojan.LynceBir.A requires careful and systematic steps to ensure that all components of the malware are eliminated from your system. By understanding how Trojans operate and following the removal guidance provided, you can effectively regain control of your system and protect your data. Remember, prevention is key; maintaining updated antivirus software, being cautious with email attachments and downloads, and regularly scanning your system can help prevent future infections.

Analysis Report

General information

Family Name: Trojan.LynceBir.A
Signature status: No Signature

Known Samples

MD5: 934cda3ed7323c36fbd7930ff3f4f4f7
SHA1: 219ea34ab41b64c057e80413558352766d413219
File Size: 96.04 KB, 96036 bytes
MD5: 236d91d02f4aa5c2ef5b52c955c0cfda
SHA1: b0d00add1e734abbf7ba22e6f0ac4a86f397fc3a
SHA256: 924F1D1516BF73CDBCC912DE60A12B0256BA7033109B6F47645328009B351264
File Size: 60.42 KB, 60416 bytes
MD5: c7dd0558ee390599ee34501a41f8edf0
SHA1: 24505bc76792328e97aea5e16e55a7dd851ced59
SHA256: 309F2FAFFBCFA12CF9DE6574A7043F51C4EB07CDFBD0135AD25067E145DD4C22
File Size: 2.27 MB, 2265088 bytes
MD5: a885a003bfca82a22996b4173300e87c
SHA1: 530ef2112c6b8206f3a2b74040b465f65d19afd9
SHA256: 7B743CD7F362FDD62D5988185704A46914A299B599D553628DED4D3AB9C9822F
File Size: 393.44 KB, 393436 bytes
MD5: 45ffd1336bc56a318dae6bed2047be5f
SHA1: 161650a30adcb08460d5b952fac952e88ba465e6
SHA256: E3274B5FB0FF4C3810E71615F6251282D49E271FC63AA04C9F0D4A364B3DF895
File Size: 13.82 KB, 13824 bytes
Show More
MD5: a93edd9897210ea0e5f99e42b99674c5
SHA1: 55530708fa0e353c2f7344929f03f130ac46be03
SHA256: 749B32EE591D5AD0A48DF0800702785FCA1AB60A066532A7861B9DFF252437AF
File Size: 111.34 KB, 111341 bytes
MD5: 9f8a7eeebc7d8dd55b77b059996ef6cb
SHA1: 81c67997d7f030ce83e7f718ab80631314e840e0
SHA256: 28F02FB45605C72543A9C49C2786F28776EAF618F99233A97B254E1A45A5DE06
File Size: 7.34 MB, 7335652 bytes
MD5: 8e8a8abcb836e6d08e41885881773460
SHA1: 1f8c8816f72c9e5e3596a3224ccd8355fdfcb3ed
SHA256: 9F202729CE47D8205407050E27309C4C666115C81C999A07013354A38CB71FD3
File Size: 60.92 KB, 60925 bytes
MD5: 8ee9a91772ea2e0e033a82c3d9dd6f4f
SHA1: 8deab2286ab499f2e4a77fd5b55a2da0192da0e7
SHA256: 5194C6F4CDF7A0E416250E533F6D012181E86AB89B19624D159092CC37979248
File Size: 7.17 KB, 7168 bytes
MD5: 4229878e89ec40ac480ed4973b8ae1e4
SHA1: 4da3c251047af6a62613acf4cdd16149cb2b8c14
SHA256: 19D681797AB156A7275E72A1FDDB749F3B62998C3026674651FD1D973CB1E37F
File Size: 123.19 KB, 123193 bytes
MD5: 944cc6d64f5e2efcb0bc7158b58fbde0
SHA1: db123c886974ba0d3dbdc5b741b633b7150d22cf
SHA256: 24AA0BA8279F506D01EAB4941689A2526E7C01BF9E895A539CE808DB2A0E80F8
File Size: 126.93 KB, 126934 bytes
MD5: 7e96f8c2be22b79cedb2a8f6f8267aba
SHA1: 58880c83632d222ee0d0c5d2eee2120fc775c1b4
SHA256: 451C93ABDE573A94FFC81F4510AA98FF38E0E81B56DCFFD36B38F5BB392ED2DA
File Size: 37.41 KB, 37413 bytes
MD5: 298f9d9d3ff1a7f94b6f2948372d69cb
SHA1: 028630b9953bba06f30447784f74b4ef64745cd6
SHA256: 1A6150E31F0778C0D3E733B0313516C574A320147524C39381B733F8B067C7A9
File Size: 6.42 MB, 6417870 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File has been packed
  • File has TLS information
  • File is .NET application
  • File is 32-bit executable
Show More
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.23.0
Comments
  • COMPUTERBILD-Abzockschutz-Installer (1.0.23 Online)
  • This installation was built with Inno Setup.
  • www.boraxsoft.de
Company Name
  • Boraxsoft
  • Grenouille - C'MON
  • J3S GmbH
  • n37
File Description
  • COMPUTERBILD-Abzockschutz-Installer
  • Developed using the Dev-C++ IDE
  • GUI for dvdauthor installer (Full)
  • Pause
  • PyGrenouille Setup
File Version
  • 1.0.23.0
  • 0.99
Internal Name
  • COMPUTERBILD-Abzockschutz-Installer.exe
  • Dunno
Legal Copyright
  • Bill Gates
  • Copyright © COMPUTERBILD GmbH
  • © Boraxsoft
Legal Trademarks Bill Gates
Original Filename COMPUTERBILD-Abzockschutz-Installer.exe
Product Name
  • COMPUTERBILD-Abzockschutz-Installer
  • GUI for dvdauthor
  • PyGrenouille
Product Version 1.0.23.0

File Traits

  • No Version Info
  • packed
  • x86

Block Information

Similar Families

  • Dialer.X
  • Kindal.B
  • LynceBir.A

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsb404d.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\downloads\frp-ll Generic Write,Read Attributes
c:\users\user\downloads\frp-st Generic Write,Read Attributes
c:\users\user\downloads\frp-st_1 Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\downloads\frp-st_1 Synchronize,Write Attributes
c:\users\user\downloads\lv.rnd Generic Write,Read Attributes
c:\windows\appcompat\programs\amcache.hve Read Data,Read Control,Write Data
c:\windows\appcompat\programs\amcache.hve.log1 Read Data,Write Data
c:\windows\appcompat\programs\amcache.hve.log2 Read Data,Write Data

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAdjustPrivilegesToken
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
Show More
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtLoadKeyEx
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
User Data Access
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Process Shell Execute
  • CreateProcess
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Network Info Queried
  • GetAdaptersInfo

Shell Command Execution

C:\Windows\Microsoft.NET\Framework64\v2.0.50727\\dw20.exe dw20.exe -x -s 868