Please enable JavaScript to view this site.

Support Site User Guide

Category:   Viruses and Spyware                

Type:                Trojan

Aliases:       Sinowal

                   Anserin

Affected Operating Systems: Windows

 

Summary

Torpig is a type of botnet spread by a variety of trojan horses which can affect computers that use Microsoft Windows. Torpig circumvents anti-virus applications through the use of rootkit technology and scans the infected system for credentials, accounts and passwords as well as potentially allowing attackers full access to the computer. It is also purportedly capable of modifying data on the computer, and can perform man-in-the-browser attacks.

 

Installation

The Trojan downloads and executes additional files from a remote site. Configuration files may also be downloaded which define further behaviors. Troj/Torpig-A is a Trojan for the Windows platform.

When run, Troj/Torpig-A creates a subfolder under the Windows system folder named "service" and creates the following files:

<Windows system folder>\service\dll.dll

<Windows system folder>\service\dllp.txt

<Windows system folder>\service\explorer.exe

 

The dll.dll file is a keylogging component while the dllp.txt file is used for data storage.

In order to run each time a user logs on, Troj/Torpig-A sets the following registry entry:

HKCU\Software\Microsoft\Windows\CurrentVersion\Runexplorer

<Windows system folder>\service\explorer.exe

 

The Trojan logs keypresses and open window titles to text files and periodically sends the collected information to a remote user via HTTP.

The Trojan downloads and executes additional files from a remote site. Configuration files may also be downloaded which define further behaviors.

Troj/Torpig-A automatically closes security warning messages displayed by common anti-virus and security related applications.

 

The Trojan may set several entries under the following registry locations:

HKCU\Software\Microsoft\Windows\CurrentVersion\pwd

HKCU\Software\Microsoft\Windows\CurrentVersion\gnum

HKCU\Software\Microsoft\Windows\CurrentVersion\myID2

 

Removal

If you are using Sophos please follow the below link for removal instructions.

http://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/Troj~Torpig-A.aspx

 

If the Sophos scan does not work you can try using the guide found at the link provided.

(The below guide is not written by Wavenet Education or LGfL so it is used at your own risk)

http://www.securitystronghold.com/gates/torpig.html

Return to main page