|
What is Lydra and removal instructions
Lydra is a trojan that steals user some sensitive information and transfers it to a predetermined remote server. The parasite can bypass the Windows Firewall. It secretly runs on every Windows startup.
The newest version of Lydra can turn-off some anti-virus applications, log key-strokes and send collected information through its own emailing engine.
Lydra manual removal: Kill processes: calc.exe, lsassv.exe, msrpc.exe, regedit.exe, winsys.exe
Delete registry values: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\lsassv
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\winsys
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\winsys
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\winsys
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\winsys
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\msrpc
HKEY_CLASSES_ROOT\CLSID\
|
|
|
|
|