Saturday, December 6, 2008

VBS.Toren Trojan

How To Remove VBS.Toren?
You must download trial version of "Exterminate-It" antivirus software,to check your computer instantly.
VBS.Toren is dangerous virus:
This loose category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Multi-purpose Trojans are also included in this group, as some virus writers
create multi-functional Trojans rather than Trojan packs.


VBS.Toren It also known as:

[Kaspersky]Trojan.VBS.Toren;
[Panda]VBS/Sanz;
[Computer Associates]VBS/Toren!Trojan

VBS.Toren Symptoms:

Files:
[%DESKTOP%]\easy mp3 alarm clock.lnk
[%SYSTEM%]\stub.exe
[%DESKTOP%]\easy mp3 alarm clock.lnk
[%SYSTEM%]\stub.exe

Folders:
[%PROGRAMS%]\easy mp3 alarm clock
[%PROGRAM_FILES%]\easy mp3 alarm clock

Registry Keys:
HKEY_CLASSES_ROOT\appid\ezulabootexe.exe
HKEY_CLASSES_ROOT\appid\{c0335198-6755-11d4-8a73-0050da2ee1be}
HKEY_CLASSES_ROOT\clsid\{07f0a543-47ba-11d4-8a6d-0050da2ee1be}
HKEY_CLASSES_ROOT\clsid\{07f0a545-47ba-11d4-8a6d-0050da2ee1be}
HKEY_CLASSES_ROOT\clsid\{19dfb2cb-9b27-11d4-b192-0050dab79376}
HKEY_CLASSES_ROOT\clsid\{2079884b-6ef3-11d4-8a74-0050da2ee1be}
HKEY_CLASSES_ROOT\clsid\{2babd334-5c3f-11d4-b184-0050dab79376}
HKEY_CLASSES_ROOT\clsid\{3d7247e8-5db8-11d4-8a72-0050da2ee1be}
HKEY_CLASSES_ROOT\clsid\{55910916-8b4e-4c1e-9253-cce296ea71eb}
HKEY_CLASSES_ROOT\clsid\{58359010-bf36-11d3-99a2-0050da2ee1be}
HKEY_CLASSES_ROOT\clsid\{c03351a4-6755-11d4-8a73-0050da2ee1be}
HKEY_CLASSES_ROOT\clsid\{c4fee4a7-4b8b-11d4-8a6d-0050da2ee1be}
HKEY_CLASSES_ROOT\clsid\{d290d6e7-bf9d-42f0-9c1b-3bc8ae769b57}
HKEY_CLASSES_ROOT\ezulaagent.ezulactrlhost
HKEY_CLASSES_ROOT\ezulaagent.ezulactrlhost.1
HKEY_CLASSES_ROOT\ezulaagent.plugprot
HKEY_CLASSES_ROOT\ezulaagent.plugprot.1
HKEY_CLASSES_ROOT\ezulaagent.toolbarband
HKEY_CLASSES_ROOT\ezulaagent.toolbarband.1
HKEY_CLASSES_ROOT\ezulabootexe.installctrl
HKEY_CLASSES_ROOT\ezulabootexe.installctrl.1
HKEY_CLASSES_ROOT\ezulamain.ezulasearchpipe
HKEY_CLASSES_ROOT\ezulamain.ezulasearchpipe.1
HKEY_CLASSES_ROOT\interface\{07f0a542-47ba-11d4-8a6d-0050da2ee1be}
HKEY_CLASSES_ROOT\interface\{07f0a544-47ba-11d4-8a6d-0050da2ee1be}
HKEY_CLASSES_ROOT\interface\{1823bc4b-a253-4767-9cfc-9aca62a6b136}
HKEY_CLASSES_ROOT\interface\{19dfb2ca-9b27-11d4-b192-0050dab79376}
HKEY_CLASSES_ROOT\interface\{27bc6871-4d5a-11d4-8a6d-0050da2ee1be}
HKEY_CLASSES_ROOT\interface\{3d7247f1-5db8-11d4-8a72-0050da2ee1be}
HKEY_CLASSES_ROOT\interface\{4fd8645f-9b3e-46c1-9727-9837842a84ab}
HKEY_CLASSES_ROOT\interface\{58359012-bf36-11d3-99a2-0050da2ee1be}
HKEY_CLASSES_ROOT\typelib\{07f0a536-47ba-11d4-8a6d-0050da2ee1be}
HKEY_CLASSES_ROOT\typelib\{58359011-bf36-11d3-99a2-0050da2ee1be}
HKEY_CLASSES_ROOT\typelib\{8a044396-5da2-11d4-b185-0050dab79376}
HKEY_CLASSES_ROOT\typelib\{c0335197-6755-11d4-8a73-0050da2ee1be}
HKEY_LOCAL_MACHINE\software\classes\appid\ezulabootexe.exe
HKEY_LOCAL_MACHINE\software\classes\appid\{c0335198-6755-11d4-8a73-0050da2ee1be}
HKEY_LOCAL_MACHINE\software\classes\clsid\{07f0a543-47ba-11d4-8a6d-0050da2ee1be}
HKEY_LOCAL_MACHINE\software\classes\clsid\{07f0a545-47ba-11d4-8a6d-0050da2ee1be}
HKEY_LOCAL_MACHINE\software\classes\clsid\{19dfb2cb-9b27-11d4-b192-0050dab79376}
HKEY_LOCAL_MACHINE\software\classes\clsid\{2079884b-6ef3-11d4-8a74-0050da2ee1be}
HKEY_LOCAL_MACHINE\software\classes\clsid\{2babd334-5c3f-11d4-b184-0050dab79376}
HKEY_LOCAL_MACHINE\software\classes\clsid\{3c368c4a-827f-4f25-9c52-371bdf049912}
HKEY_LOCAL_MACHINE\software\classes\clsid\{3d7247e8-5db8-11d4-8a72-0050da2ee1be}
HKEY_LOCAL_MACHINE\software\classes\clsid\{55910916-8b4e-4c1e-9253-cce296ea71eb}
HKEY_LOCAL_MACHINE\software\classes\clsid\{58359010-bf36-11d3-99a2-0050da2ee1be}
HKEY_LOCAL_MACHINE\software\classes\clsid\{c03351a4-6755-11d4-8a73-0050da2ee1be}
HKEY_LOCAL_MACHINE\software\classes\clsid\{c4fee4a7-4b8b-11d4-8a6d-0050da2ee1be}
HKEY_LOCAL_MACHINE\software\classes\clsid\{d290d6e7-bf9d-42f0-9c1b-3bc8ae769b57}
HKEY_LOCAL_MACHINE\software\classes\ezulaagent.ezulactrlhost
HKEY_LOCAL_MACHINE\software\classes\ezulaagent.ezulactrlhost.1
HKEY_LOCAL_MACHINE\software\classes\ezulaagent.plugprot
HKEY_LOCAL_MACHINE\software\classes\ezulaagent.plugprot.1
HKEY_LOCAL_MACHINE\software\classes\ezulaagent.toolbarband
HKEY_LOCAL_MACHINE\software\classes\ezulaagent.toolbarband.1
HKEY_LOCAL_MACHINE\software\classes\ezulabootexe.installctrl
HKEY_LOCAL_MACHINE\software\classes\ezulabootexe.installctrl.1
HKEY_LOCAL_MACHINE\software\classes\ezulamain.ezulasearchpipe
HKEY_LOCAL_MACHINE\software\classes\ezulamain.ezulasearchpipe.1
HKEY_LOCAL_MACHINE\software\classes\interface\{07f0a542-47ba-11d4-8a6d-0050da2ee1be}
HKEY_LOCAL_MACHINE\software\classes\interface\{07f0a544-47ba-11d4-8a6d-0050da2ee1be}
HKEY_LOCAL_MACHINE\software\classes\interface\{1823bc4b-a253-4767-9cfc-9aca62a6b136}
HKEY_LOCAL_MACHINE\software\classes\interface\{19dfb2ca-9b27-11d4-b192-0050dab79376}
HKEY_LOCAL_MACHINE\software\classes\interface\{27bc6871-4d5a-11d4-8a6d-0050da2ee1be}
HKEY_LOCAL_MACHINE\software\classes\interface\{3d7247f1-5db8-11d4-8a72-0050da2ee1be}
HKEY_LOCAL_MACHINE\software\classes\interface\{4fd8645f-9b3e-46c1-9727-9837842a84ab}
HKEY_LOCAL_MACHINE\software\classes\interface\{58359012-bf36-11d3-99a2-0050da2ee1be}
HKEY_LOCAL_MACHINE\software\classes\interface\{7edc96e1-5dd3-11d4-b185-0050dab79376}
HKEY_LOCAL_MACHINE\software\classes\interface\{8ebb1743-9a2f-11d4-8a7e-0050da2ee1be}
HKEY_LOCAL_MACHINE\software\classes\interface\{c03351a3-6755-11d4-8a73-0050da2ee1be}
HKEY_LOCAL_MACHINE\software\classes\interface\{c4fee4a6-4b8b-11d4-8a6d-0050da2ee1be}
HKEY_LOCAL_MACHINE\software\classes\interface\{ef0372dc-f552-11d3-8528-0050dab79376}
HKEY_LOCAL_MACHINE\software\classes\interface\{ef0372de-f552-11d3-8528-0050dab79376}
HKEY_LOCAL_MACHINE\software\classes\typelib\{07f0a536-47ba-11d4-8a6d-0050da2ee1be}
HKEY_LOCAL_MACHINE\software\classes\typelib\{58359011-bf36-11d3-99a2-0050da2ee1be}
HKEY_LOCAL_MACHINE\software\classes\typelib\{c0335197-6755-11d4-8a73-0050da2ee1be}


You must clean you computer ASAP !!!
Download Free Trial Version of antivirus software here, to check your computer instantly.

Also Be Aware of the Following Threats:
Removing ICMPNemesy DoS
Vxidl.BBX Trojan Removal instruction
Cobfinn Trojan Symptoms

No comments: