Remove Lydra. Description and removal instructions

 
Title: Lydra

Type: Trojans
Severity scale:Lydra severity is 50  (50 / 100)
 
Lydra is a trojan that steals user some sensitive information and transfers it to a predetermined remote server. The parasite can bypass the Windows Firewall. It secretly runs on every Windows startup.
The newest version of Lydra can turn-off some anti-virus applications, log key-strokes and send collected information through its own emailing engine.


Related files: Calc.exe, lsassv.exe, msrpc.exe, regedit.exe, winsys.exe, iecomn.dll, pool32.dll, setupiwz.dll, unrar.dll, viaud.dll, rctfd.sys, adobegammaloader.scr

Lydra properties:
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic Lydra removal:

remover for Lydra

Lydra manual removal:

Kill processes:
calc.exe, lsassv.exe, msrpc.exe, regedit.exe, winsys.exe
Delete registry values:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\lsassv
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\winsys
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\winsys
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\winsys
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\winsys
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\msrpc
HKEY_CLASSES_ROOT\CLSID\{65D5AFFB-D4EF-49AA-GFFG-5DA5E12E300A}
Delete files:
calc.exe, lsassv.exe, msrpc.exe, regedit.exe, winsys.exe, iecomn.dll, pool32.dll, setupiwz.dll, unrar.dll, viaud.dll, rctfd.sys, adobegammaloader.scr
Misc:
Exact file location:
adobegammaloader.scr - C:\Documents and Settings\All Users\Start Menu\Programs\Startup
calc.exe, lsassv.exe, msrpc.exe, regedit.exe, winsys.exe, iecomn.dll, pool32.dll, setupiwz.dll, unrar.dll, viaud.dll, rctfd.sys - C:\WINDOWS or C:\WINNT

Other programs to remove Lydra:

• SUPERAntiSpyware - Review - Download
• CounterSpy - Review - Download
• Windows Defender - Review - Download

Information added: 20/12/06
Information updated: 20/12/06

Additional resources related to Lydra:

Attention: If you know or you have a website or page about Lydra removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Lydra parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Latest spyware news:
Similar parasites: