Spy Trojan

TrojanSpy:Win32/Larks.A removal

Malware Removal

The TrojanSpy:Win32/Larks.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Larks.A virus can do?

  • Executable code extraction
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine TrojanSpy:Win32/Larks.A?


File Info:

crc32: 9FE744DA
md5: 2bc406aa8f45c1fbb5bab073b4c53313
name: 2BC406AA8F45C1FBB5BAB073B4C53313.mlw
sha1: 61a12ba4e2fa91caabc3899a86edc3976c1ab46d
sha256: 50163b4d76bcb570f30b6093c02987cab31459463434fb35dcec2fcb444ac252
sha512: 6907f9174515026c346e6987ba46d8eb5f9a1aefbd5db19ad56e328aaabcd1a38ea26ad872ba80a1ef73c501cc12575f535460d5e2fa1cce8c4f4ac111a33a40
ssdeep: 768:qXCXyMMZShA4AvN3vILkaGh73MTWqyYaFvW2Nr9wgjcI+E:pyMMbNfILk6abYI+E
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: Microsoft Corporation
InternalName: dasdasdas
FileVersion: 1.00
CompanyName: Microsoft Corporation
LegalTrademarks: Microsoft Corporation
Comments: Microsoft Corporation
ProductName: Microsoft LifeCam
ProductVersion: 1.00
FileDescription: Host Process for Windows Services
OriginalFilename: dasdasdas.exe

TrojanSpy:Win32/Larks.A also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Kazy.4997
ALYacGen:Variant.Kazy.4997
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Blocker.j!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0053260d1 )
BitDefenderGen:Variant.Kazy.4997
K7GWTrojan ( 0053260d1 )
Cybereasonmalicious.a8f45c
BitDefenderThetaAI:Packer.E6F668A120
CyrenW32/Risk.XJLW-5564
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/PSW.VB.NFJ
BaiduWin32.Trojan.VB.hj
APEXMalicious
AvastWin32:Rootkit-gen [Rtk]
ClamAVWin.Ransomware.Vbmalware-9786411-0
KasperskyTrojan-Ransom.Win32.Blocker.iwdz
NANO-AntivirusTrojan.Win32.Scar.eclufy
ViRobotTrojan.Win32.Scar.49152.E
RisingRansom.Blocker!8.12A (CLOUD)
Ad-AwareGen:Variant.Kazy.4997
EmsisoftGen:Variant.Kazy.4997 (B)
ComodoTrojWare.Win32.Trojan.Generic.32301750@2ne5et
F-SecureTrojan.TR/Crypt.FKM.Gen
DrWebTrojan.MulDrop3.1425
TrendMicroTROJ_FAM_0001115.TOMA
McAfee-GW-EditionGeneric.cza
FireEyeGeneric.mg.2bc406aa8f45c1fb
SophosML/PE-A + Mal/VB-EX
IkarusTrojan.Win32.VB
JiangminTrojan/Generic.kqcx
AviraTR/Crypt.FKM.Gen
MAXmalware (ai score=82)
Antiy-AVLTrojan[Ransom]/Win32.Blocker
MicrosoftTrojanSpy:Win32/Larks.A
ArcabitTrojan.Kazy.D1385
AhnLab-V3Trojan/Win32.Scar.R4224
ZoneAlarmTrojan-Ransom.Win32.Blocker.iwdz
GDataGen:Variant.Kazy.4997
CynetMalicious (score: 90)
McAfeeGeneric.cza
VBA32Trojan.VBRA.02803
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_FAM_0001115.TOMA
TencentWin32.Trojan.Blocker.Hupw
YandexTrojan.GenAsa!Hzgk9R3kjRw
SentinelOneStatic AI – Suspicious PE
FortinetW32/VB.EX!tr
AVGWin32:Rootkit-gen [Rtk]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Win32/Trojan.Ransom.abb

How to remove TrojanSpy:Win32/Larks.A?

TrojanSpy:Win32/Larks.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment