Welcome to remove-malware.net
The ultimate resource for malware removal and virus protection
How to remove Lsas.Trojan-Spy.DOS.Keycopy malware
Malware Description:
Lsas.Trojan-Spy.DOS.Keycopy is a framed-up digital infection actively used in the scareware campaign pushing the rogue security product called Malware Destructor 2009. Actually, Lsas.Trojan-Spy.DOS.Keycopy appears on the fake Windows Security Alerts issued by Malware Destructor 2009 in order to mislead unsuspecting victims. According to those bogus ads, Lsas.Trojan-Spy.DOS.Keycopy “is suspected to have infected your PC”. The popup also notifies the user that Lsas.Trojan-Spy.DOS.Keycopy is capable of tracking the personal data to further transmit it to a remote IP address. Whichever option you choose on that phony Windows Security Alert, you will trigger the installation of Malware Destructor 2009, or get redirected to a website like Malwaresdestructor.com which advertises the rogue anti-spyware under consideration. Whenever you start getting strange popup ads entitled “Windows Security Alert” and mentioning Lsas.Trojan-Spy.DOS.Keycopy infection as a trojan endangering your computer – you should realize you are being brainwashed into installing rogue anti-spyware which wants you money. Lsas.Trojan-Spy.DOS.Keycopy is a mere bait to sugarcoat the malicious intensions of the cyber-criminals who developed Malware Destructor scareware. Whenever you encounter Lsas.Trojan-Spy.DOS.Keycopy, make sure you check your cyber-space for trojans and Malware Destructor 2009 trialware which may be hiding in the depths of your system without you knowing it.
Malware Type: Trojan Horses
Malware Author: dreamakerlab
Threat Level: ![]()
![]()
![]()
![]()
Critical
Advice: Immediately remove and scan for additional malware
Lsas.Trojan-Spy.DOS.Keycopy Free Scanner and Remover:
Download Now
Screenshot of Fake Alert Mentioning Lsas.Trojan-Spy.DOS.Keycopy:

How to remove Lsas.Trojan-Spy.DOS.Keycopy and related malware manually:
Manual removal of Lsas.Trojan-Spy.DOS.Keycopy and the associated rogue is feasible if you have sufficient expertise in working with program files, system processes, .dll files and registry entries.
The files to be deleted are listed below:
- %UserProfile%\Application Data\Malware Destructor 2009
- %UserProfile%\Application Data\Malware Destructor 2009\cookies.sqlite
- %UserProfile%\Application Data\Malware Destructor 2009\Instructions.ini
- %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Malware Destructor 2009.lnk
- %UserProfile%\Desktop\Malware Destructor 2009.lnk
- %UserProfile%\Local Settings\Temp\del.bat
- %UserProfile%\Recent\ANTIGEN.exe
- %UserProfile%\Recent\ANTIGEN.sys
- %UserProfile%\Recent\cb.drv
- %UserProfile%\Recent\energy.exe
- %UserProfile%\Recent\energy.tmp
- %UserProfile%\Recent\FS.sys
- %UserProfile%\Recent\FS.tmp
- %UserProfile%\Recent\FW.dll
- %UserProfile%\Recent\hymt.exe
- %UserProfile%\Recent\kernel32.drv
- %UserProfile%\Recent\PE.dll
- %UserProfile%\Recent\PE.tmp
- %UserProfile%\Recent\tempdoc.exe
- %UserProfile%\Recent\tjd.tmp
- %UserProfile%\Start Menu\Malware Destructor 2009.lnk
- %UserProfile%\Start Menu\Programs\Malware Destructor 2009.lnk
- %Documents and Settings%\All Users\Application Data\345d567
- %Documents and Settings%\All Users\Application Data\345d567\384.mof
- %Documents and Settings%\All Users\Application Data\345d567\MD345d.exe
- %Documents and Settings%\All Users\Application Data\345d567\mozcrt19.dll
- %Documents and Settings%\All Users\Application Data\345d567\sqlite3.dll
- %Documents and Settings%\All Users\Application Data\345d567\MDestrSys
- %Documents and Settings%\All Users\Application Data\345d567\MDestrSys\vd952342.bd
- %Documents and Settings%\All Users\Application Data\MDestrSys
- %Documents and Settings%\All Users\Application Data\MDestrSys\mdestr.cfg
- %WINDOWS%\Temp\IMT7.xml
- %WINDOWS%\Temp\IMT8.xml
- %WINDOWS%\Temp\IMT9.xml
The associated registry entries to be removed are as follows:
- HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
- HKEY_CLASSES_ROOT\MD345d.DocHostUIHandler
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\
Please, be informed that manual removal of Lsas.Trojan-Spy.DOS.Keycopy is a cumbersome procedure and does not always ensure complete deletion of the malware, since some files might be hidden or may automatically reanimate themselves afterwards. Moreover, manual interference of this kind may cause damage to the system. That’s why we strongly recommend automatic removal of Lsas.Trojan-Spy.DOS.Keycopy which will save your time and enable avoiding any system malfunctions and guarantee the needed result.
| Download Lsas.Trojan-Spy.DOS.Keycopy Automatic Remover |
Like This Article? Let Others Know!
Related Articles:
How to remove Lsas.Blaster.Keylogger Trojan
How to remove Malware Destructor 2009 rogue anti-spyware
How to remove Malware Catcher 2009 rogue anti-spyware
How to remove Trojan.win32.agent.azsy trojan
Page Info:
-
June 18, 2009 -
0 comments
-
Comments RSS
Make it social:
Latest Removal Guides
Types of Malware
- Adware (6)
- Browser Hijackers (732)
- Fake Security Programs (109)
- Mac Scareware (1)
- Ransomware (4)
- Rogue Anti-Spyware (736)
- Security Alerts (30)
- Spyware (2)
- Toolbars (4)
- Trojan Horses (94)
- Worms (31)
