Threat Database Trojans Win32/Lethic.AA

Win32/Lethic.AA

Win32/Lethic.AA is a deceptive Trojan horse. Win32/Lethic.AA can load into memory when Windows is booted making it very difficult to manually remove. Win32/Lethic.AA can lead to the installation of other malware without the computer user's knowledge or consent. Performance of a computer and its network can be greatly reduced from the installation of the Win32/Lethic.AA Trojan. Win32/Lethic.AA can be very difficult to manually remove due to its ability to load into memory once Windows is booted.

File System Details

Win32/Lethic.AA may create the following file(s):
# File Name Detections
1. %RECYCLER%\S-1-5-21-0243556031-888888379-781863308-1455\psysnew.exe

Registry Details

Win32/Lethic.AA may create the following registry entry or registry entries:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "psysnew" = "%RECYCLER%\S-1-5-21-0243556031-888888379-781863308-1455\psysnew.exe"
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon "shell" = "%RECYCLER%\S-1-5-21-0243556031-888888379-781863308-1455\psysnew.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon "Taskman" = "%RECYCLER%\S-1-5-21-0243556031-888888379-781863308-1455\psysnew.exe"

Trending

Most Viewed

Loading...