Solved! Use LVVM.EXE (Backdoor Cycbot) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

LVVM.EXE – Backdoor Cycbot removal

File MD5 Virus Alias
LVVM.EXE 40d9607cb66da11b9adfec5b93b8b311 Backdoor Cycbot
LVVM.EXE 40d9607cb66da11b9adfec5b93b8b311 Trojan XPACK
LVVM.EXE 40d9607cb66da11b9adfec5b93b8b311 Trojan Generic
LVVM.EXE 40d9607cb66da11b9adfec5b93b8b311 Trojan Eldorado
LVVM.EXE 40d9607cb66da11b9adfec5b93b8b311 Trojan Downloader
LVVM.EXE 40d9607cb66da11b9adfec5b93b8b311 Trojan Menti

LVVM.EXE size: 174080 bytes
LVVM.EXE hash: 40D9607CB66DA11B9ADFEC5B93B8B311

Created files:

%Program Files%\Internet Explorer\lvvm.exe
%AppData%\A4FA.159
%UserProfile%\awhost.exe
%UserProfile%\cwhost.exe
%UserProfile%\d3WQGzd9.exe
%UserProfile%\dwhost.exe
%UserProfile%\saereq.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\conhost: %Program Files%\Internet Explorer\lvvm.exe

Detected by UnHackMe:

LVVM.EXE
Default location: %PROGRAM FILES%\INTERNET EXPLORER\LVVM.EXE

Dropper information:
MD5: c5d7197a4117b73ac2ff1e730c1ca5d2
File size: 860160 bytes

Leave a Reply