Home Malware Programs Trojans Trojan.Win32.Tirnod

Trojan.Win32.Tirnod

Posted: June 1, 2011

Trojan.Win32.Tirnod is a seditious computer trojan that installs on a computer system without a targeted user's knowledge when he/she tries to open an unidentified email attachment or image, use instant messaging, etc. Trojan.Win32.Tirnod can block an affected user from accessing legitimate websites and redirects him/her to visit unwanted criminal websites. Anti-virus software find it very complicated to detect Trojan.Win32.Tirnod as it disguises itself in the root of the PC system. Trojan.Win32.Tirnod can slow down your PC system by capturing the system resources. Trojan.Win32.Tirnod makes its occurrence in the registry files and starts automatically every time you start the computer. Remove Trojan.Win32.Tirnod immediately so as to protect your computer.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\encdeqk.dat
    2 %System%\ifsutig.dat
    3 %System%\mstlsapc.dat
    4 %System%\mstlsapc.ocx
    5 %System%\netshelz.dat
    6 %System%\Packutz.dat

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F426925F-92C1-388C-2295-03B6BC95A97A}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F426925F-92C1-388C-2295-03B6BC95A97A}\InprocServer32HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\mstlsapc
Loading...