Threat indicator: HIGH

Perfil de amenaza

Nombre de la amenaza:

Comando o nombre de archivo:

Tipo de amenaza:

Afectado SO:




Win32 (Windows XP, Vista, Seven, 8)

Metodo de intrusion de Torpig

Torpig copia su archivo (s) a su disco duro. Su tipico nombre de archivo es regscanr.exe. Entonces se crea una nueva clave de inicio con el nombre Torpig y valor regscanr.exe. Tambien lo puede encontrar en la lista de procesos con el nombre regscanr.exe o Torpig.

Si usted tiene mas preguntas sobre Torpig, por favor complete el siguiente formulario y nos pondremos en contacto con usted pronto.

Es importante:

  1. Odiamos el spam tanto como usted. No compartiremos su correo electronico con terceros o publicar en cualquier lugar. Tu email solo se utiliza para ponerse en contacto con usted y le dara solucion de eliminacion de Torpig.
  2. Todos los campos de este formulario son obligatorios.

Software Industry Professionals Member
La descripcion de la amenaza y la solucion son desarrollados por Security Stronghold equipo de seguridad.

Aqui tambien se puede aprender:

* ?Que es Torpig? Los detalles tecnicos de Torpig problema y programa de eliminacion de Torpig.

* Los metodos para remocion manual de Torpig.

* Descarga instantanea de un programa que va a resolver su problema de forma automatica.

Como eliminar Torpig de forma manual?

Este problema se puede resolver de forma manual mediante la supresion de todas las claves de registro y archivos relacionados con Torpig, sacarlo de la lista de inicio y anular el registro de todos los archivos DLL correspondientes. DLL que faltan, ademas, deben ser restaurados de distribucion en caso de que sean danados por Torpig.

Para deshacerse de Torpig, usted debe:

1. Mata a los siguientes procesos y eliminar los archivos adecuados:

  • ibm00003.exe
  • 897586e9.exe
  • 36.tmp3072.exe
  • ibm00001.dll
  • ibm00002.dll
  • $_2341234.tmp
  • $_2341233.tmp
  • $_2341235.tmp
  • $b17a2e8.tmp
  • $_3472452.EXE
  • file_3.exe
  • file_4.exe
  • file_5.exe
  • inserv[1].exe
  • inserv.exe
  • msvbs32[1].dll
  • msvbs32.dll
  • ld_dnv[1].exe
  • ld_grey[1].exe
  • ld_ment[1].exe
  • ld_ovr[1].exe
  • vx.exe
  • clea14418.dll

Advertencia: debe eliminar solo los archivos que checksums se enumeran como malicioso. Es posible que haya archivos validos con los mismos nombres en su sistema. Le recomendamos que utilizar Utilidad de eliminacion de Torpig para la solucion de un problema de seguridad.

2. Elimine las siguientes carpetas maliciosos:

  • %commonprogramfiles%\microsoft shared\web folders\

3. Elimine las siguientes entradas en el registro maliciosos:

  • Key: System\CurrentControlSet\Services\ldrsvc\DisplayName
  • Key: System\CurrentControlSet\Services\gb\DisplayName
  • Key: SYSTEM\ControlSet001\Enum\Root\LEGACY_LDRSVC\0000\Control
    Value: ActiveService
    Value: *NewlyCreated*
  • Key: SYSTEM\CurrentControlSet\Services\ldrsvc\Parameters
    Value: ServiceDll
  • Key: Software\Microsoft\Windows\CurrentVersion\Run
    Value: 897586e9.exe
  • Key: Software\Microsoft\Windows\CurrentVersion\Run
    Value: Windows update loader
  • Key: software\microsoft\windows\currentversion\run
    Value: 897586e9.exe
  • Key: software\microsoft\windows\currentversion\run
    Value: windows update loader
  • Key: Software\Microsoft\Windows\CurrentVersion\Run
    Value: shell
  • Key: System\CurrentControlSet\Services\ldrsvc
    Value: Type
  • Key: System\CurrentControlSet\Services\ldrsvc
    Value: Start
  • Key: System\CurrentControlSet\Services\ldrsvc
    Value: ErrorControl
  • Key: System\CurrentControlSet\Services\ldrsvc
    Value: ImagePath
  • Key: System\CurrentControlSet\Services\ldrsvc\Security
    Value: Security
  • Key: System\CurrentControlSet\Services\ldrsvc
    Value: ObjectName
    Value: NextInstance
    Value: *NewlyCreated*
    Value: Service
    Value: Legacy
    Value: ConfigFlags
    Value: Class
    Value: ClassGUID
    Value: DeviceDesc
    Value: Count
    Value: NextInstance
  • Key: System\CurrentControlSet\Enum\Root\LEGACY_LDRSVC\0000\Control
    Value: ActiveService
  • Key: System\CurrentControlSet\Services\gb
    Value: Type
  • Key: System\CurrentControlSet\Services\gb
    Value: Start
  • Key: System\CurrentControlSet\Services\gb
    Value: ErrorControl
  • Key: System\CurrentControlSet\Services\gb
    Value: ImagePath
  • Key: System\CurrentControlSet\Services\gb
    Value: DisplayName
  • Key: System\CurrentControlSet\Services\gb\Security
    Value: Security
  • Key: System\CurrentControlSet\Services\gb
    Value: ObjectName
  • Key: SYSTEM\CurrentControlSet\Services\gb\Parameters
    Value: ServiceDll
    Value: NextInstance
    Value: Service
    Value: Legacy
    Value: ConfigFlags
    Value: Class
    Value: ClassGUID
    Value: DeviceDesc
    Value: Count
    Value: NextInstance
  • Key: System\CurrentControlSet\Enum\Root\LEGACY_GB\0000\Control
    Value: ActiveService
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
    Value: Wallpaper
    Data: %windows%\desktop.html
  • Key: SYSTEM\CurrentControlSet\Enum\Root\LEGACY_LDRSVC\0000
    Value: Driver
  • Key: SYSTEM\ControlSet001\Services\ldrsvc\Parameters
    Value: ServiceDll
  • Key: SYSTEM\ControlSet001\Enum\Root\LEGACY_LDRSVC\0000
    Value: Driver
  • Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon
    Value: Shell
    Data: explorer.exe "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe"

Advertencia: si el valor esta en la lista de algunas entradas del registro, solo se debe limpiar estos valores y dejar las llaves con tales valores intactos. Le recomendamos que utilizar Utilidad de eliminacion de Torpig para la solucion de un problema de seguridad.

4. Fijar problemas con el navegador manualmente

Torpig puede afectar a su navegador que se traduce en la redireccion del navegador o la busqueda de secuestro. Le recomendamos que utilice la opcion libre "Reset Browsers" bajo "Tools" en Spyhunter Remediation Tool para restablecer todos los navegadores a la vez. Mencione que usted necesita para eliminar todos los archivos y matar a todos los procesos que pertenecen al Torpig antes de hacer esto. Para reiniciar su navegador manualmente y restaurar tu pagina de inicio realice los pasos siguientes:

internet explorer logo

Internet Explorer

  • Si utiliza Windows XP, clic Inicio, y luego clic Ejecutar. Escriba lo siguiente en el Ejecutar caja sin comillas, y pulse Entrar: "inetcpl.cpl"

  • Si utiliza Windows 7 o Windows Vista, clic Inicio boton. Escriba lo siguiente en el Buscar caja sin comillas, and press Entrar: "inetcpl.cpl"

  • Haga clic en el Opciones avanzadas

  • In Restablecer configuracion de Internet Explorer, clic Restablecer... Clic Restablecer en la ventana abierta otra vez.

  • Seleccionar la casilla Eliminar configuaracion personal para eliminar el historial de navegacion, los proveedores de busquedas, pagina principal

  • Despues de Internet Explorer termine de restablecer, clic Cerrar en el cuadro de dialogo Restablecer configuracion de Internet Explorer

google chrome logo

Google Chrome

  • Vaya a la carpeta de instalacion de Google Chrome: C:\Users\"su nombre de usuario"\AppData\Local\Google\Chrome\Application\User Data.

  • En el carpeta de User Data, buscar un archivador llamado Default y cambie su nombre DefaultBackup.

  • Lanzar Google Chrome y se creara una nueva limpia archivador Default.

mozilla firefox logo

Mozilla Firefox

  • Abre Firefox

  • Ir a Ayuda > Informacion para solucionar problemas en menu.

  • Clic en Restablecer Firefox... boton.

  • Una vez que finalice Firefox, se mostrara una ventana y crear una carpeta en el escritorio. Clic Terminar.

Advertencia: En caso de que esta opcion no funcionara el uso libre opcion Restablecer navegadores bajo Tools menu en Utilidad de eliminacion de Torpig.

Informacion proporcionada por: Aleksei Abalmasov

Here are the descriptions of problems connected with Torpig and regscanr.exe we received earlier:

Problem Summary: Cannot send email. Reported as torpig problem

I have reveived this message when sending email.

An error occurred sending mail: The mail server sent an incorrect greeting: nskntcmgw06p BigPond Outbound [OB105. Connection refused. is listed on the Exploits Block List (XBL). Please visit for more information..

My ip address checks out.. as the one listed above.
This page tells me..
IP Address is listed in the CBL. It appears to be infected with a spam sending trojan, proxy or some other form of botnet.

It was last detected at 2013-05-16 08:00 GMT (+/- 30 minutes), approximately 2 days, 21 hours ago.

This IP is infected with, or is NATting for a machine infected with Torpig, also known by Symantec as Anserin.

Problem was successfully solved. Ticket was closed.

Problem Summary: I have not been able to play many of the games I like to play

Well I was playing games I like to play. Minecraft espeacially. My server I play on has something that can stop hacks like this from getting on. I suddenly am infected and I cannot join this server. Please help

Problem was successfully solved. Ticket was closed.

Problem Summary: I have not been able to play many of the games I like to play

Well I was playing games I like to play. Minecraft espeacially. My server I play on has something that can stop hacks like this from getting on. I suddenly am infected and I cannot join this server. Please help

Problem was successfully solved. Ticket was closed.

Problem Summary: Torpig trojan horse virus

I got a letter from my internet provider wich says my laptop is infected with the torpig virus and I need to remove it within 5 days. My collega's said I need to download a programm wich will delete it and my laptop is going to be fine. Could you please tell me exactly what to do and what programms to download? Thank you in advance.

Problem was successfully solved. Ticket was closed.

Problem Summary: torpig

hi i got a letter from my internet provider which says i have a torpig virus on my computer and if i do not fix it within 5 days they will shut my internet down for a temporarly time. I have searched for many solutions but i cant find any solutios for it.
Also another problem is the letter says its on my computer but i got 3 here so i also dont know on what computer it is. What is the solution to get rid off of the torpig?

Problem was successfully solved. Ticket was closed.

Problem Summary: torpig trojan horse

hi i got a letter from my internet provider which says i have a torpig virus on my computer and if i do not fix it within 5 days they will shut my internet down for a temporarly time. I have searched for many solutions but i cant find any solutios for it.
Also another problem is the letter says its on my computer but i got 3 here so i also dont know on what computer it is. What is the solution to get rid off of the torpig?

Problem was successfully solved. Ticket was closed.

Problem Summary: rapport say i have a torpig

trusteer rapport say i have a torpig i have downloaded several scanners andnothing has worked

Problem was successfully solved. Ticket was closed.

Problem Summary: Notice from Qwest of bot/malware

Qwest stating our computer has a Malware Type identified as Mebroot and/or Torpig. When the computer is turned on, a blue screen pops up and some sort of systems check scan is run and thenthe computer reboots. When we log onto the internet BING pops up twice as our home page and then the Google home page pops up. Google is the home page. Then MSN error message comes up and closes down the internet. Hope this is sufficient. Thanks

Problem was successfully solved. Ticket was closed.

Problem Summary: Continued spam to one link from one friends mailbox.

Problem was successfully solved. Ticket was closed.

Problem Summary: How to remove torpig trojan virus - Is your Torpig removal free?

My bank deactivated my online access because it says that I have the Torpig trojan virus at my IP address. At my IP address I have two computers: one, a Mac laptop and the other a Dell laptop. McAfee Plus is on theDell laptop but did not detect Torpig. Currently McAfee is running a virus scan (after I called them to complain) and that scan has not finished yet. I wonder if the Mac is infected but do not have McAfee on the Mac. I do not know which laptop I used two days ago that caused the bank alert. Bank access has Trusteer Rapport that detected Torpig. No other banking institutions have so alerted me.

Problem was successfully solved. Ticket was closed.

