Solved! Use LPHCAPRJ0EG9J.EXE (Rootkit TDSS) Removal Guide

I will tell you in this post how to fix the issue manually and how to clean it automatically using a special powerful removal tool. You can download the removal program for free here:

Manual removal instructions:

LPHCAPRJ0EG9J.EXE – Rootkit TDSS removal

File MD5 Virus Alias
LPHCAPRJ0EG9J.EXE d787f7d0e2797144b1fe55d9eb6fc790 Rootkit TDSS
LPHCAPRJ0EG9J.EXE d787f7d0e2797144b1fe55d9eb6fc790 Trojan Generic
LPHCAPRJ0EG9J.EXE d787f7d0e2797144b1fe55d9eb6fc790 Trojan Downloader
LPHCAPRJ0EG9J.EXE d787f7d0e2797144b1fe55d9eb6fc790 Trojan Renos
LPHCAPRJ0EG9J.EXE d787f7d0e2797144b1fe55d9eb6fc790 Trojan Agent
LPHCAPRJ0EG9J.EXE d787f7d0e2797144b1fe55d9eb6fc790 Trojan Small

LPHCAPRJ0EG9J.EXE size: 186380 bytes
LPHCAPRJ0EG9J.EXE hash: D787F7D0E2797144B1FE55D9EB6FC790

Created files:

%SysDir%\blphcaprj0eg9j.scr
%SysDir%\lphcaprj0eg9j.exe
%Temp%\.tt5D.tmp.vbs

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\lphcaprj0eg9j: %WinDir%\System32\lphcaprj0eg9j.exe
HKCU\Control Panel\Desktop\SCRNSAVE.EXE: %WinDir%\System32\blphcaprj0eg9j.scr

Detected by UnHackMe:

LPHCAPRJ0EG9J.EXE
Default location: %SYSDIR%\LPHCAPRJ0EG9J.EXE

Dropper information:
MD5: d787f7d0e2797144b1fe55d9eb6fc790
File size: 186380 bytes

Leave a Reply