• Home
  • Regtweaker
  • Subscribe to Posts
  • Subscribe to comments

PC solutions

Give you Professional Suggestions

  • Home
  • News
  • Registry
  • Script
  • System Utility
  • Virus
  • Windows
  • XML
Home Virus Manually remove Backdoor.Win32.Trup.bo

Manually remove Backdoor.Win32.Trup.bo

Posted on Wednesday, 8 June 2011
23 Comments
Share|

virus Name: backdoor.Win32.Trup.bo

Risk level: Medium

Virus Description

The virus sample size is “39,424 bytes” and the extension is “. Exe”, it is mainly through the “file bundle”, “download tool to download”, “web page linked to horses” and other ways to spread, the main purpose of this virus the user’s IE browser hijacking, tampering home page, when the user’s computer infected, will access a large number of the designated website and download a large number of unknown trojan to your computer, the system is running Slow, slow speed, a large number of unknown processes.

Infection in the operating system

Windows 2000/Windows XP / Windows 2003/Windows Vista / Windows 7

Transmission

Bundle file, web page linked to horse, download tools to download

Manual Solution:

1. Kill the use of desktop software to scan and clean up a comprehensive tool for system cleaning.
2. Delete the Registry entries
HKEY_CLASSES_ROOT \ SOFTWARE \ Classes \ JE
HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ JE
The registry key to normal
HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ IE \ shell \ open \ command

Variable declaration:

% SystemDriver% system where the partition, usually “C: \”
% SystemRoot% WINDODWS directory, usually “C: \ Windows”
% Documents and Settings% user file directory, usually “C: \ Documents and Settings”
% Temp% temp folder, usually “C: \ Documents and Settings \ current user name \ Local Settings \ Temp”
% ProgramFiles% system program the default installation directory, typically: “C: \ ProgramFiles”
Virus:

(1), creating a snapshot of the process, traversing 360 security guards to find the existence of anti-virus module process DsMain.exe, if there is its dormancy.
(2), create% SystemRoot% \ Sie.ini configuration file. Create multiple threads, create% SystemDriver% \ alh.exe, create a process execution alh.exe, moving itself as 228.tmp, and set the hidden attribute. Hidden file extensions, do not show hidden files, so as to achieve the effect of the virus itself hidden.
(3), remote into the iexplore.exe process, and access http://www.xun ***. info. Create Registry
HKEY_CLASSES_ROOT \ SOFTWARE \ Classes \ JE and HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ JE
Key: command
Data:% ProgramFiles% \ Internet Explorer \ IEXPLORE.EXE http://www.xun ***. info,
Item: DefaultIcon
Data:% SystemRoot% \ system32 \ tbhdz.ico
(4), modify the registry HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ IE \ shell \ open \ command is% ProgramFiles% \ Internet Explorer \ IEXPLORE.EXE http:// **. 97780.com? 1127311, tampering home to http: //**. 97780.com? 1127311, visit the designated website and download a large number of Trojan viruses into the IE buffer, download large files to the user’s computer to run an unknown.
(5), create a rogue on the desktop shortcut: IE browser, Taobao shop, online way of high definition theater and other shortcuts.

Virus to create  files:

% SystemRoot% \ VL.ini
% SystemRoot% \ al.ini%
SystemRoot% \ VB.ini
% SystemRoot% \ system32 \ tbhdz.ico
% SystemDriver% \ ati.exe
Virus current directory \ 288.tmp
Virus current directory \ 1288.tmp

Virus to create the registry:

HKEY_CLASSES_ROOT \ SOFTWARE \ Classes \ JE
HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ JE

Modify the HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ IE \ shell \ open \ command
Value:% ProgramFiles% \ Internet Explorer \ IEXPLORE.EXE http:// **. 97780.com? 1127311

Virus to access the network:

http://dh.765 ***. info? 1127311
http://dh.977 **. com
http://cpm.ejiu **. com / sms / tc.php? id = 10
http://cpm.ejiu **. com / sms / tc.php? id = 11
http://cpm.ejiu **. com / sms / tc.php? id = 12
http://jj.765 ***. info: 3218/sms/xxx5.ini
http://60.173.10 .**: 4567/setup_10016.exe
http://xiazai .*****. com/Corp/kugou_2526.exe
http://60.173.10 .**: 1234/dy.exe


Share this Post:
Digg Google Bookmarks reddit Mixx StumbleUpon Technorati Yahoo! Buzz DesignFloat Delicious BlinkList Furl
Tagged with: Backdoor.Win32, Backdoor.Win32 removal

23 Responses to “Manually remove Backdoor.Win32.Trup.bo”

Trackbacks are disabled.

Saluda IN foundation repair
security systems Seaside NY
play casino games
sensual massage,
Gander Mountain coupons
work accident solicitor
  • gol videoları says:
    2011-08-15 at 5:37 am

    spor haberleri…

    iddaa programı…

  • ukash kart says:
    2011-08-14 at 9:54 am

    superbahis…

    superbahis giriş…

  • Health says:
    2011-08-12 at 8:26 am

    Health Articles…

    Health…

  • lumix waterproof camera says:
    2011-08-9 at 8:34 am

    lumix waterproof camera…

    waterproof camera…

  • borsa says:
    2011-08-9 at 5:15 am

    borsa…

    borsa haberleri…

  • polyester su depoları says:
    2011-08-6 at 5:47 am

    su depolari…

    polyester su depoları…

  • beyazlatma says:
    2011-08-2 at 3:23 pm

    beyazlatma…

    implant…

  • kabin özellikleri says:
    2011-08-2 at 7:15 am

    kabin özellikleri…

    su deposu…

  • isyeri says:
    2011-07-31 at 1:12 am

    isyeri…

    arsa…

  • tente çeşitleri says:
    2011-07-30 at 4:08 am

    tente sistemleri…

    tente çeşitleri…

  • escort bayan says:
    2011-07-29 at 8:42 am

    oohh clon nice for…

    this is peretkalus…

  • Cazibeli resimler says:
    2011-07-27 at 1:11 pm

    Cazibeli resim…

    Cazibeli resimler…

  • dizi izle says:
    2011-07-27 at 1:54 am

    film izle…

    dizi izle…

  • moda says:
    2011-07-27 at 12:59 am

    dekorasyon…

    moda…

  • eternity rings says:
    2011-07-26 at 5:54 am

    eternity rings…

    eternity rings…

  • film izle says:
    2011-07-21 at 4:35 am

    film izle…

    film izle…

  • temizlik şirketleri says:
    2011-07-19 at 12:20 am

    temizlik şirketleri…

    temizlik şirketleri…

  • Leave a Reply:

    Click here to cancel reply.

    Name (required):
    Mail (will not be published) (required):
    Website:
    Comment (required):
    XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>
    验证图片
    刷新验证码
    *

    Popular Articles

      • How to uninstall pc optimizer pro, pc optimizer pro removal 1139 comment(s)
      • what is Pbupdate.exe and how to fix Pbupdate.exe error? 1138 comment(s)

    latest comments

    • 正在加载...

    Tags

      Antivirus Suite Autorun ave.exe Backdoor Backdoor.Win32 Backdoor.Win32 removal browser home page was altered cc Clicker.dj Clunky Backdoor removal Default home page is modified DLL files error DOMDocument->load() downloader encountered Fix Kernel32 Dll Error MAC Microsoft Security Essentials PSW PSW.Kykymber.cc registry was modified remove MyWinLocker remove regedit32.exe remove safedrv.exe remove Trojan.Win32.Buzus.a Run command slow computer Speed Up Computer speed up pc Trojan Trojan-Downloader.Win32.Small.b removal Trojan-PSW.Win32 Trojan.Win32 Trojan.Win32 removal Trojan Downloader Trojan Dropper uninstall MyWinLocker variant dj Virus W32.Cervivec.A@mm Win32 Win32.Hack.GrayBird.al.761856 Win32.TrojDownloader.Guupk.ps Worm Worm.Win32

    Category

    • News
    • Others
    • Registry
    • Script
    • System Utility
    • Virus
    • Windows
    • XML

    Archives

    • December 2011
    • November 2011
    • October 2011
    • September 2011
    • July 2011
    • June 2011
    • May 2011
    • April 2011
    • March 2011
    • February 2011

    Links

    • Download Drivers

    Pages

    • Regtweaker
    • Spyware Cease
    
    Copyright © 2012 PC solutions. Powered by VersionHunter.com. registry repair |Threats Center
    Top