Remove Tarno.r. Description and removal instructions

 
Title: Tarno.r

Type: Trojans
Severity scale:Tarno.r severity is 65  (65 / 100)
 
Tarno.r is a trojan that monitors application windows and accessed web pages for predefined keywords. Once the parasite detects such a keyword, it starts recording all the keystrokes that the user enters into various window fields and web forms. Gathered data is saved to several files, which are regularly transferred to a predetermined remote web server.

Tarno.r arrives in bogus e-mail with malicious executable attachements. Once the user runs such an attachment, the trojan secretly downloads its main components from the Internet and installs itself to the system. Tarno.r is able to bypass the Windows Firewall.

The trojan works as an Internet Explorer add-on and therefore runs every time the user launches the web browser.


Tarno.r properties:
• Logs keystrokes
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic Tarno.r removal:

remover for Tarno.r

Tarno.r manual removal:

Kill processes:
file1185.exe, ndppbzn.exe, winsetup.exe
Delete registry values:
HKEY_CLASSES_ROOT\CLSID\{3A4E6FF3-BF59-446E-9DC8-731BCE2F349A}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\svchost.Update
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3A4E6FF3-BF59-446E-9DC8-731BCE2F349A}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\[filename]
Unregister DLLs:
svchost.dll

Delete files:
file1185.exe, ndppbzn.exe, winsetup.exe, svchost.dll, sui.dll, update.sys, wint.ini, ierror.rep
Delete directories:
C:\Windows\System\arcada
C:\Windows\System32\arcada
C:\Winnt\System32\arcada

C:\Windows\System\svact
C:\Windows\System32\svact
C:\Winnt\System32\svact

C:\Windows\System\svcontr
C:\Windows\System32\svcontr
C:\Winnt\System32\svcontr

C:\Windows\System\svskn
C:\Windows\System32\svskn
C:\Winnt\System32\svskn
Misc:
The file1185.exe file arrives attached to Tarno.r e-mail messages.

Exact file location:
update.sys - C:
winsetup.exe, svchost.dll, sui.dll, wint.ini, ierror.rep - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32

Other programs to remove Tarno.r:

• SUPERAntiSpyware - Review - Download
• CounterSpy - Review - Download
• Windows Defender - Review - Download

Information added: 24/01/06
Information updated: 24/01/06

Additional resources related to Tarno.r:

Attention: If you know or you have a website or page about Tarno.r removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Tarno.r parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Latest spyware news:
Similar parasites: