W32.Tozap

By LoneStar in Worms

Threat Scorecard

Threat Level: 50 % (Medium)
Infected Computers: 2
First Seen: March 28, 2012
Last Seen: February 11, 2023
OS(es) Affected: Windows

W32.Tozap is a dangerous worm that uses removable drives to spread itself. W32.Tozap also opens a back door on the corrupted machine by connecting to the specific domains. When run, W32.Tozap starts to replicate itself. W32.Tozap creates infectious files and modifies the Windows Registry so that it can launch whenever you start your computer. W32.Tozap may fulfill harmful activities on the affected computer that involve reading Mozilla Firefox profile information, downloading and executing files and executing UDP flooding. You need to remove W32.Tozap as early as possible before it destroys your computer.

File System Details

W32.Tozap may create the following file(s):
# File Name Detections
1. %Temp%\Program.exeadobe-master-cs4-keygen..exe
2. %DriveLetter%\winlog.exe
3. %DriveLetter%\autorun.inf

Registry Details

W32.Tozap may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"winlog.exe" = "%UserProfile%\Application Data\Microsoft\winlog.exe"

URLs

W32.Tozap may call the following URLs:

blnq-search.com

Trending

Most Viewed

Loading...