Home Malware Programs Trojans Win32/Lethic.AA

Win32/Lethic.AA

Posted: April 2, 2010

Win32/Lethic.AA is a dangerous Trojan parasite. Win32/Lethic.AA can lead to other malware parasite infections and greatly reduce the performance of a computer and its network. Win32/Lethic.AA is also known as irTool:Win32/DelfInject.gen!BH, P2P-Worm.Win32.Palevo.rmm and Generic.dx!nns Trojan. Detection and removal of Generic.dx!nns Trojan is recommended to be performed by a spyware detection tool to safely remove any files associated with Win32/Lethic.AA.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %RECYCLER%\S-1-5-21-0243556031-888888379-781863308-1455\psysnew.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon "shell" = "%RECYCLER%\S-1-5-21-0243556031-888888379-781863308-1455\psysnew.exe"HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "psysnew" = "%RECYCLER%\S-1-5-21-0243556031-888888379-781863308-1455\psysnew.exe"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon "Taskman" = "%RECYCLER%\S-1-5-21-0243556031-888888379-781863308-1455\psysnew.exe"
Loading...