Trojan.Win32.Larchik.v
Trojan.Win32.Larchik.v Description
Trojan.Win32.Larchik.v is a dangerous Trojan horse that may be involved in botnet activities. Trojan.Win32.Larchik.v may be distributed via contaminated websites or unsolicited spam e-mails. Trojan.Win32.Larchik.v may download malicious files onto a compromised PC. Trojan.Win32.Larchik.v may also affect the operation of a system and should be removed immediately to limit further damages.
Type: Trojans
How Can You Detect Trojan.Win32.Larchik.v?
Trojan.Win32.Larchik.v has typically the following processes in memory:
- %System%\IEShortcut.exe
- %Windir%\Temp\syccom\Source.exe
- %System%\5.exe
- %Windir%\Temp\syccom\Setup.exe
- %System%\27a.exe
- %System%\tubiao111111.exe
Trojan.Win32.Larchik.v creates the following registry entries:
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5B3CF2C3-BB2E-B124-4351-1B3D6CB6CD21}\Shell
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5B3CF2C3-BB2E-B124-4351-1B3D6CB6CD21}\Shell\D
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5B3CF2C3-BB2E-B124-4351-1B3D6CB6CD21}\Shell\Open\Command
- HKEY_CURRENT_USER\Software\WinRAR SFX
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5B3CF2C3-BB2E-B124-4351-1B3D6CB6CD21}\DefaultIcon
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5B3CF2C3-BB2E-B124-4351-1B3D6CB6CD21}\Shell\??(&R)\Command
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5B3CF2C3-BB2E-B124-4351-1B3D6CB6CD21}\Shell\Open
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{5B3CF2C3-BB2E-B124-4351-1B3D6CB6CD21}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5B3CF2C3-BB2E-B124-4351-1B3D6CB6CD21}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5B3CF2C3-BB2E-B124-4351-1B3D6CB6CD21}\Shell\??(&R)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5B3CF2C3-BB2E-B124-4351-1B3D6CB6CD21}\Shell\D\Command
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5B3CF2C3-BB2E-B124-4351-1B3D6CB6CD21}\ShellFolder
Important Article Disclaimer
This entry was posted on 11/5/09 and is filed under Trojans.
You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

English 
Deutsch
Español
Français
Portuguese
Trojan.Win32.Larchik.v 











