Sophos

Troj/Larx-A

Aliases
  • Trojan-PSW.Win32.Agent.eg
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from August 2006 (4.08)
Protection available since 25 May 2006 22:27:50 (GMT)
Last updated 26 June 2006 21:10:03 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Larx-A is a Trojan for the Windows platform.

When first run Troj/Larx-A copies itself to C:\NEWTRO\IEXPLORE.COM and creates the file C:\NEWTRO\NEWTRO.DLL.

Troj/Larx-A sets one of the following registry entries to run IEXPLORE.COM on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
NEWTRO
C:\NEWTRO\IEXPLORE.COM

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit
<Windows folder>\system32\userinit.exe,C:\NEWTRO\IEXPLORE.COM

(the default value for this registry entry is "<Windows folder>\System32\userinit.exe,").

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer