Home Malware Programs Malware Malware.Lurkasys

Malware.Lurkasys

Posted: November 20, 2009

Malware.Lurkasys is a malicious malware program which infects your PC and modifies other files by overwriting them. Malware.Lurkasys can drop additional threats onto the computer before spreading by infecting executable files on local and shared drives. Malware.Lurkasys may also include spyware that monitors your Internet activity and programs that change your web browser or dialup settings. Do not show this cyber menace any mercy and have Malware.Lurkasys termintaed immediately.

Aliases

Virus.Win32.Virut.n (Kaspersky Lab)
W32/Lurka.a (McAfee)
PE_LURKER.A (Trend Micro)
W32/Lurka-A (Sophos)
Virus:Win32/Lurka.A (Microsoft)
IM-Worm.Win32.VB (Ikarus)

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\WinSit.exe
    2 %Temp%\10.tmp
    3 %Temp%\11.tmp
    4 %Windir%\dc.exe
    5 %Windir%\Help\Other.exe
    6 %Windir%\inf\Other.exe
    7 %Windir%\SVIQ.EXE
    8 %Windir%\system\Fun.exe
    9 %Windir%\wininit.ini
    10 [file and pathname of the sample #1]

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
Loading...