Trojan.Win32.Larchik.v
Trojan.Win32.Larchik.v Description
Trojan.Win32.Larchik.v is a dangerous Trojan horse that may be involved in botnet activities. Trojan.Win32.Larchik.v may be distributed via contaminated websites or unsolicited spam e-mails. Trojan.Win32.Larchik.v may download malicious files onto a compromised PC. Trojan.Win32.Larchik.v may also affect the operation of a system and should be removed immediately to limit further damages.
Type: Trojans
Automatic Detection of Trojan.Win32.Larchik.v
Trojan.Win32.Larchik.v has typically the following processes in memory:
- %System%\IEShortcut.exe
- %Windir%\Temp\syccom\Source.exe
- %System%\5.exe
- %Windir%\Temp\syccom\Setup.exe
- %System%\27a.exe
- %System%\tubiao111111.exe
Trojan.Win32.Larchik.v creates the following registry entries:
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5B3CF2C3-BB2E-B124-4351-1B3D6CB6CD21}\Shell
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5B3CF2C3-BB2E-B124-4351-1B3D6CB6CD21}\Shell\D
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5B3CF2C3-BB2E-B124-4351-1B3D6CB6CD21}\Shell\Open\Command
- HKEY_CURRENT_USER\Software\WinRAR SFX
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5B3CF2C3-BB2E-B124-4351-1B3D6CB6CD21}\DefaultIcon
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5B3CF2C3-BB2E-B124-4351-1B3D6CB6CD21}\Shell\??(&R)\Command
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5B3CF2C3-BB2E-B124-4351-1B3D6CB6CD21}\Shell\Open
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{5B3CF2C3-BB2E-B124-4351-1B3D6CB6CD21}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5B3CF2C3-BB2E-B124-4351-1B3D6CB6CD21}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5B3CF2C3-BB2E-B124-4351-1B3D6CB6CD21}\Shell\??(&R)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5B3CF2C3-BB2E-B124-4351-1B3D6CB6CD21}\Shell\D\Command
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5B3CF2C3-BB2E-B124-4351-1B3D6CB6CD21}\ShellFolder
Important Article Disclaimer

This entry was posted
on 11/5/09 and is filed under Trojans.
You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.

English 

Trojan.Win32.Larchik.v 










