Home Malware Programs Worms W32.Tozap

W32.Tozap

Posted: March 28, 2012

Threat Metric

Threat Level: 5/10
Infected PCs: 5
First Seen: March 28, 2012
Last Seen: February 11, 2023
OS(es) Affected: Windows

W32.Tozap is a computer worm that circulates through removable drives. W32.Tozap also opens a back door on the infected computer system by connecting to the particular websites. Once executed, W32.Tozap creates copies of itself. W32.Tozap also creates malicious files and modifies the Windows Registry so that it can start each time you boot up Windows. W32.Tozap may execute malicious actions on the corrupted PC that include downloading and executing files, reading Mozilla Firefox profile information and accomplishing UDP flooding. Uninstall W32.Tozap in order to keep your PC safe and clean.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%DriveLetter%\winlog.exe File name: %DriveLetter%\winlog.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%DriveLetter%\autorun.inf File name: %DriveLetter%\autorun.inf
Mime Type: unknown/inf
Group: Malware file
%Temp%\Program.exeadobe-master-cs4-keygen..exe File name: %Temp%\Program.exeadobe-master-cs4-keygen..exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"winlog.exe" = "%UserProfile%\Application Data\Microsoft\winlog.exe"

Additional Information

The following URL's were detected:
blnq-search.com
Loading...