LYS.001 – KeyLogger Ardamax

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

LYS.001 – KeyLogger Ardamax removal

File MD5 Virus Alias
LYS.001 c7fbfdd2d7ded71b4b6281efa26eeede KeyLogger Ardamax
LYS.001 c7fbfdd2d7ded71b4b6281efa26eeede Trojan SuspiciousFile
LYS.001 c7fbfdd2d7ded71b4b6281efa26eeede Trojan Generic
LYS.001 c7fbfdd2d7ded71b4b6281efa26eeede Trojan CI
LYS.001 c7fbfdd2d7ded71b4b6281efa26eeede Worm AMN
LYS.001 c7fbfdd2d7ded71b4b6281efa26eeede Trojan Graftor

LYS.001 size: 70656 bytes
LYS.001 hash: C7FBFDD2D7DED71B4B6281EFA26EEEDE

Created files:

%SysDir%\OXICEU\AKV.exe
%SysDir%\OXICEU\LYS.001
%SysDir%\OXICEU\LYS.002
%SysDir%\OXICEU\LYS.003
%SysDir%\OXICEU\LYS.004
%SysDir%\OXICEU\LYS.005
%SysDir%\OXICEU\LYS.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\LYS Start: %WinDir%\System32\OXICEU\LYS.exe

Detected by UnHackMe:

LYS.001
Default location: %SYSDIR%\OXICEU\LYS.001

Dropper information:
MD5: 004fb073a037479e9185f6c089d075eb
File size: 1427456 bytes

Leave a Reply