Solved! Use LSM.EXE (Trojan Graftor) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

LSM.EXE – Trojan Graftor removal

File MD5 Virus Alias
LSM.EXE 00e5ea04c184368881f6dd0efdcf2161 Trojan Graftor
LSM.EXE 00e5ea04c184368881f6dd0efdcf2161 Trojan, Suspicious File
LSM.EXE 00e5ea04c184368881f6dd0efdcf2161 Trojan Ransom
LSM.EXE 00e5ea04c184368881f6dd0efdcf2161 Trojan Generic
LSM.EXE 00e5ea04c184368881f6dd0efdcf2161 Trojan Eldorado
LSM.EXE 00e5ea04c184368881f6dd0efdcf2161 Trojan Downloader

LSM.EXE size: 273408 bytes
LSM.EXE hash: 00E5EA04C184368881F6DD0EFDCF2161

Created files:

%WinDir%\System\logman.exe
%WinDir%\System\lsm.exe
%AppData%\Microsoft\lsm.exe
%AppData%\wininit.exe
%Local AppData%\ieudinit.exe
%Temp%\Twain002.Mtx

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\Logman: %WinDir%\System\logman.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\lsm service: %WinDir%\System\lsm.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\IEudInit: %Local AppData%\ieudinit.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\lsm service: %AppData%\Microsoft\lsm.exe

Detected by UnHackMe:

LSM.EXE
Default location: %WinDir%\SYSTEM\LSM.EXE

Dropper information:
MD5: 00e5ea04c184368881f6dd0efdcf2161
File size: 273408 bytes

Leave a Reply