Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 3 June 2005 12:55:11 (GMT) |
| Detected by | All Sophos products |
- Endpoint Security and Control 9.0
- Small business solutions 4.0
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Zarcry-A is a browser hijacking Trojan.
Troj/Zarcry-A will attempt to redirect web traffic intended for "google" to a predefined website.
When first run, Troj/Zarcry-A will create the following files:
<System>\rch.dll - Troj/Zarcry-A
<System>\rch32.dll - data file containing an encrypted URL
<System>\rdrlib.dll - Troj/Zarcry-A
Troj/Zarcry-A will attempt to inject code into other processes.
Troj/Zarcry-A will set the following registry entry:
HKCR\CLSID\(03B1C4D9-BC71-8916-38AD-9DEA5D213614)\InProcServer32
(default)
<System>\rch.dll
and one of the following registry entries:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\(03B1C4D9-BC71-8916-38AD-9DEA5D213614)
HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\(03B1C4D9-BC71-8916-38AD-9DEA5D213614)
