LYS.003 – KeyLogger Ardamax

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

LYS.003 – KeyLogger Ardamax removal

File MD5 Virus Alias
LYS.003 c6f4f0917a9deb025840a5713e32e731 KeyLogger Ardamax
LYS.003 c6f4f0917a9deb025840a5713e32e731 Trojan SuspiciousFile
LYS.003 c6f4f0917a9deb025840a5713e32e731 Trojan Generic
LYS.003 c6f4f0917a9deb025840a5713e32e731 Trojan Eldorado
LYS.003 c6f4f0917a9deb025840a5713e32e731 Trojan Downloader
LYS.003 c6f4f0917a9deb025840a5713e32e731 Trojan Bumat

LYS.003 size: 78848 bytes
LYS.003 hash: C6F4F0917A9DEB025840A5713E32E731

Created files:

%SysDir%\OXICEU\AKV.exe
%SysDir%\OXICEU\LYS.001
%SysDir%\OXICEU\LYS.002
%SysDir%\OXICEU\LYS.003
%SysDir%\OXICEU\LYS.004
%SysDir%\OXICEU\LYS.005
%SysDir%\OXICEU\LYS.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\LYS Start: %WinDir%\System32\OXICEU\LYS.exe

Detected by UnHackMe:

LYS.003
Default location: %SYSDIR%\OXICEU\LYS.003

Dropper information:
MD5: 004fb073a037479e9185f6c089d075eb
File size: 1427456 bytes

Leave a Reply