• Home
  • Regtweaker
  • Subscribe to Posts
  • Subscribe to comments

PC solutions

Give you Professional Suggestions

  • Home
  • News
  • Registry
  • Script
  • System Utility
  • Virus
  • Windows
  • XML
Home Virus manually remove Trojan-Downloader.Win32.Small.b

manually remove Trojan-Downloader.Win32.Small.b

Posted on Monday, 6 September 2010
972 Comments
Share|

trojan downloader: Trojan-Downloader.Win32.Small.b

Risk level: Medium

virus Description

The sample is a “downloaders” which is  developed by the “VC” , size “32,811″ bytes, the icon is “remove Trojan-Downloader.Win32.Small.b“, use the “exe” extension, through the bundled documentation, web pages linked to horse, download tools to download, etc. and spread. The main purpose is to download the virus Trojan horse virus.
When the user’s computer is infected with this trojan virus, there will be no reason the system error, anti-virus software does not start automatically quit and found a large number of unknown processes, etc..

Infected OS

Windows 2000/Windows XP / Windows 2003/Windows Vista / Windows 7

Transmission

File bound, Page Trojan, download tools to download

Manual removal:


Manually delete files

1. Delete% Temp% \ setup.exe
2. Delete% Temp% \ set1.tmp.bat
3. Remove% Documents and Settings% \ current user \ Local Settings \ Temporary Internet Files \ Content.IE5 \ 0A01B6SV \ xxxeeeddd [1]. Exe

Manually delete the Registry

1. Delete
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ DownloadManager
Name:
Data: CacheOk

2. Delete
HKEY_CLASSES_ROOT \ CLSID \ (20D04FE0-3AEA-1069-A2D8-08002B30309D)

\ InProcServer32
Name: ThreadingModel
Data: Apartment

3. Delete
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ ShellCompatibility

\ Objects \ (20D04FE0-3AEA-1069-A2D8-08002B30309D)

4. Delete
HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ Explorer \ MountPoints2 \ (897ed10a-7e49-11df-bd9f-806d6172696f)
Name: BaseClass
Data: Drive

Variable declaration:

% SystemDriver% system where the partition, typically “C: \”
% SystemRoot% WINDODWS directory, usually “C: \ Windows”
% Documents and Settings% user documentation directory, usually “C: \ Documents and Settings”
% Temp% temp folder, usually “C: \ Documents and Settings \ current user name \ Local Settings \ Temp”
% ProgramFiles% system program default installation directory, typically: “C: \ ProgramFiles”

Virus analysis:

1. The virus was the temporary directory, the directory with the command URLDownloadToFileA from the site to download setup.exe.
2. A way to hide the window, execute the file% Temp% \ setup.exe
3. To create surveillance process, the news hook the keyboard and mouse, monitor user information
4. Try to connect to the network: www .***. info, create a remote thread, from a distance file www .****. info / xxxeeeddd.exe read data to the local.
5. Create Temp% \ set1.tmp (random name), set up a batch file Temp% \ set1.tmp.bat (random name), to achieve self-delete
6. Open pipe \ \. \ Pipe \ wkssvc, \ \ pipe \ lsarpc,
7. By local IP: 127.0.0.1:1695
Connect Remote IP: 222 .189.238.246:80

The virus creates files:

% Temp% \ setup.exe
% Temp% \ set1.tmp.bat
% Documents and Settings% \ current user \ Local Settings \ Temporary Internet Files \ Content.IE5 \ 0A01B6SV \ xxxeeeddd [1]. Exe

Virus to create the registry:

HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ DownloadManager
Name:
Data: CacheOk

HKEY_CLASSES_ROOT \ CLSID \ (20D04FE0-3AEA-1069-A2D8-08002B30309D)

\ InProcServer32
Name: ThreadingModel
Data: Apartment

HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \

ShellCompatibility \ Objects \ (20D04FE0-3AEA-1069-A2D8-08002B30309D)

HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ Explorer \ MountPoints2 \ (897ed10a-7e49-11df-bd9f-806d6172696f)
Name: BaseClass
Data: Drive

Virus access to the network:

http://www .*****. info / xxxeeeddd.exe


Share this Post:
Digg Google Bookmarks reddit Mixx StumbleUpon Technorati Yahoo! Buzz DesignFloat Delicious BlinkList Furl
Tagged with: downloader, Trojan, Trojan-Downloader.Win32.Small.b removal

972 Responses to “manually remove Trojan-Downloader.Win32.Small.b”

Trackbacks are disabled.

urse valley
Views
Blanket Fleece
avon sales leadership
interior doors
Puerto Princesa Underground River
los angeles medical marijuana draft ordinance
Coping Meaning
lingam massage
thunderbolt phone
Kopa lagenhet i Antalya
siker
artisan sinks
Financial Advisers
copper bird feeders
Transparent Film
Caralluma Actives
Prepaid Kreditkarte
runescape
Occult
good injury lawyer
workout to lose man boobs
healthy weight loss supplements
Wicker Sunroom Furniture
Evil eye bracelets
Chicago Car Locksmith
tea kettle
marlo furniture rockville
lay betting system
Diabetes Symptoms
yogabis
Drake Institute
stunning clutch bags
LED Lighting
Software Training
Gaming Laptops Under 1000
cialis-giornaliero
moncler vest men
how to get friends on facebook
Personal Injury San Luis Obispo
best boston sushi
contact paper
Contact paper
E-Learning
chat roulette
nightvision
home interior gallery
healthy pregnancy
led street lights
Custom Term Papers
excel vba training courses
Motor Trade Insurance Online Quote
Sportnahrung
Licensed Professional Beauty Supplies
Radio
Payment Processing Company
Buy Cheap google likes
how to earn money from home
Elkton Florist
Chiropractic Marketing Tips
is swimming good for weight loss
top rated dating sites
cant sleep at night
plummers furniture reviews
wedding photographer atlanta
Linda
Sparta IN water in basements
Criminal Defense Attorney Tucson
Read More
Vin Dicarlo Scam
african mango plus
Nike Air Jordan Fusion 14
Lunar Elite
extreme durability
reverse phone call lookup
cosmetic surgery
e-cigaretter
Download chart music
heat pump ratings
Marijuana Laws
Foundation Financial Group
Low Carb Diet Plan
paper rolls
toronto seo
shared web hosting
printerpatron
share videos
awarded for excelling
corporate web designs
double glazed windows cost
investment property in melbourne
Flight Simulator
roomba
Eco Friendly
Weight loss
debt recovery agency
aluminium windows melbourne
new york seo
chiropractic advertising
Indica
wayfarer folding
Hardrock Hotel Penang
car care Kilsyth Vic
Car seats
hotel booking websites
meal replacement shakes
porno tube
free insurance quotes
sacramento personal injury attorney
simplex locks
sims 3 pet traits
Cheap Video Games
how to improve vision
locksmith in Houston
aluminium windows and doors
Wine of the Month Club
Get Inexpensive Auto Insurance Quotes
Get Inexpensive Auto Insurance Quotes
gynexin reviews
maquillaje profesional
Helathy Living Habbits
String Blinds
model agencies
ranch floor plans
Business
kelp supplements
Cheating on your diet
Best Baby Cribs
reverse phone trace
endlesstraffictap review
protect handbags
buy facebook likes
Movers Los Angeles
Get Inexpensive Auto Insurance Quotes
Secret Commission System
sigil tedavisi
battlefield 3 gameplay
online
personalized gifts
flash games
ohio travel bag
transmission flush cost
consumer bill help
quality cigar samplers
SEO Networker 3.0 Review
Dora Flash Games
autozone coupon
leather conditioner
Click here
Vertbaudet
northern Nevada hotels
Sears Coupon Codes
limo services in new york
Holiday Card Templates
how to host a minecraft server
cover letters
buscar pareja por internet
Thermal Imaging Surveys
Link building services
vacation holidays
alien laptop
Online Business
free texting from computer
Asics
debt advice
change pensions
stomach exercises for women at home
Orlando home inspections
japan anime
Rolex Replica Watches
Jordan 6
Chino Hills Boot Camp
betainvites.com
best gameboy advance games
Steroids
Iphone Cover Wholesale
Adventure Travel
spy cameras
Lori Bongiovanni
St. Louis Parke Roofing Company
renewable energy insurance
relik bf3 guide review
hydraulic jeans
coy wheels
yard ramp
Empower Network
Jeep Parts
black friday
Carpet Cleaning Richardson
screenshot host
secret commission system
chilewich floor mats
http://www.mediamedia.org/pg/blog/read/833872/hostgator-black-friday-this-year-low-cost-offer-80-maximum-low-cost
google sniper
emergency food supply list
medical billing software
ford crate engines
Leather handbags
acne
Lukashenko
tooth whitening
building chicken coops
Open24 login
Gunvault Biometric Gun Safes
Best Beyblade
porcelain pottery marks
Rezepte
search engine optimization orange county
Masonic Secrets
diagnostics derbyshire
coupons for sobe tea
Lv replica
KITCHEN REMODELING PORTLAND | WAYNE S. RANDALL | 503-692-3115
cocaine addiction
tagheuer
MS Project
Latterkursus
free stuff
Fitness Workout Dvds
Best trading robots
Get Your Ex Back
buy plus one votes
Wall Mount Hair Dryer
Hostgator Cyber Monday
nanny cam
Finance news Today
dating with herpes
car accident lawyer bellevue
gothic fairies
African Mango Extract
Microfinance
Car Games Online
Testosterone Supplements
Hydroxycut reviews
online business ideas
positive thinking
Financial Planning
team event
cheap travertine tiles sydney
food truck catering
grow taller for idiots review
Western Area Rugs
Grosir Kaos Polos
Paralegal Services San Jose
sea ray boats for sale
aromaterapia
immortals workout
Coffee News
best jogging strollers
Colloidal Silver the natural antibiotic
e cigs
video glasses
Empower Network
SEO UK expert
Rockwall TX Christmas Lights Installation
Torrid Promo Code
work
Schrotthandel
Alabama DUI Penalties
Cyber Monday Hosting
soccer news
data entry jobs
Bike Store
Kindle Cover
laptop
emerald cut diamonds
homemade soups
T-Shirt Konfigurator
Ribbon Microphone
pregnancy card printing
slip and fall lawyer
naija news
Used Pallet Racking
myhosting.com review
Biking
hotels in cape cod
house extensions
Backcountry
euro millions
acid reflux
Coloring Pages for Adults
Traduzione Certificata
body anatomy
Grocery coupons printable online
Hostgator Black Friday
binoculars
Trojan Printable Coupon
Bertuccis Coupon
Sporting Goods
bible verses about marriage problems
Coupon Sodastream
Plumber in Vallejo CA
Skiing
how to fix a garbage disposal
Burberry Bags
kitchen backsplash Allentown
nigerian newspapers read them online
coq10 side effects
endoscopic sinus surgery
Mountaineering
Black Friday Hosting
Purex Laundry Detergent Coupons
gotas hcg en mexico
how health insurance works
How to become a real estate investor
Search Engine
Antichrist
ocharleys Coupons Printable
Printable Aquafina Coupons
LLBean Coupons
Beyonce Pregnant
plastic cladding
landscape photographers
used cars for sale UAE
Bergners Coupons
electric underfloor heating
what to do to get money
cheap toaster oven
Web traffic
Ripstik Caster Board
chatter
math videos
aprilia rs 125
Ulang Tahun
Kue Ultah
search engine optimisation
sump pump raleigh
ipad scree protector
OnkelSeosErbe sucht Nachfolger
electronic cigarettes
All-in-one Wireless Printers
pregnancy guide
double glazed windows
buy investment property
anti-aging creams
Amsterdam Tandarts
neutrogena coupons
preparedness
Car Shipping Rates
food truck catering San Francisco
Jif Print Coupon
Affordable Online Auto Insurance Quotes
goodman furnace reviews
Buy Fine Art
investment property in melbourne
weight loss
merchant accounts
dating tips
File Personal Bankruptcy
dental tourism
Sports handicapper picks
UGG Kid's Boots
Murray Head One Night in Bangkok
Wayfinding
free sim cards
Procera AVH reviews
resume objective
iPhone 4S
best vitamins for men
debt management help
omega cabinets
top rated workout supplements
hellmans coupons
sound quality improvement
arrows
gain muscle the right way
commercial aquaponics
Sell used car
new acne treatment
top extended car coverage companies
AKO Webmail
paid to drive a car
best leadership book
villa in st lucia
Online CFD Broker vergleich
Eurochem Labs
spy gear
reliable web hosting
workout calendar
Hampton Bay Lighting
Organic food delivery
Bergners Coupon
Bertuccis Coupons Printable
brawny Coupon
Herbergers Coupons
2012 Pizza Hut Coupon Codes
ocharleys coupons
American Eagle Coupon 2012
Coupons for LLBean
estate agents edinburgh
kindle touch 3g review
Hersheys Coupons
nerf coupons
Crisco Coupons
suertres
Coupon Codes for Pizza Hut
Trojan Coupon
price of gold today
make money online
cake decorating supplies
proactol plus
Best Sewing Machine
decora cabinets
countertop paint
limo ny
cherished numbers
Obermeyer Kids
Solicitor Edinburgh
Lawyers Glasgow
Coupons For Trojan Vibrations
replacement watchband
Blog Blaster
Neutrik connectors
Plumber Arlington VA
Plumber Alexandria VA
Plumber Richmond VA
Plumber Rockville MD
Plumber Washington DC
HVAC Arlington VA
HVAC Alexandria VA
HVAC Richmond VA
best appetite suppressant
facebook password hack hacker
Speed reading courses
rosenheim
ayurvedic
tips to get your ex back
unertl scopes
iPhone Unlocking
poster printing
Resume Skills
Deer Hunting Secrets
NERF Long Strike
discount coupons brisbane
popcorn popper
Get rid of acne fast
great boobs
what does the kindle cost
Wine Gift Basket
remedies for acne
dental implants
Best Affordable Watch
Nissan dealer
X-Treme Scooters
pediatric nurse
SEO
Recipes
find insurance companies
How to reduce inflammation in the body
College textbooks
weightloss
boat plan
landscaping ideas
improving eyesight
Auto insurance quotes
french translation
Dr. Barker
  • zebra print bedding says:
    2012-04-19 at 11:16 pm

    Woah this weblog is magnificent i really like reading your posts. Stay up the good work! You realize, many persons are searching round for this info, you can help them greatly.

  • VW Dealer Albuquerque says:
    2012-04-15 at 8:42 pm

    I do believe all the concepts you have introduced on your post. They are really convincing and will certainly work. Nonetheless, the posts are too brief for novices. May you please prolong them a little from subsequent time? Thanks for the post.

  • electric scooters reviews says:
    2012-02-29 at 7:02 am

    Hi, i believe that i saw you visited my blog so i came to go back the desire?.I’m attempting to to find things to improve my site!I assume its ok to use some of your concepts!!

  • Fast Cash Commission Guy says:
    2011-10-29 at 6:23 pm

    Really quite useful blog, I personally was indeed satisfied to discover your webblog online. I decide to put a link in my blog therefore my followers might arrive at your website. Please take a glimpse.

  • film izle says:
    2011-10-27 at 9:31 pm

    good idea
    i like that
    perfect
    i can’t understand please re-write for me basic eng.
    woavv supper!! i like it
    thank you, i search it about one week

  • Kiteboarding Lessons says:
    2011-10-25 at 3:45 pm

    Kite News…

    [...]we like to bookmark other sites on the web, even if they aren’t related to us, by linking to them. Below are some sites worth checking out[...]…

  • Fiji Beach Resort says:
    2011-10-25 at 1:41 am

    Still pondering this one…

    Ever mull over where to travel to for a holiday and wind up going nowhere but wishing you had….

  • CPA Review says:
    2011-10-24 at 10:59 pm

    Goosebumps…

    Can they see these goosebumps from the incredible post….

  • Holidays In Maldives 2011 says:
    2011-10-24 at 10:57 pm

    Not exactly trending…

    Not as hot as Khan, but helpful anyway….

  • Loch Lomond Lodges says:
    2011-10-24 at 10:57 pm

    More IQ required…

    If I had another 30 IQ points, then possibly I could comprehend your post….

  • jailbreak says:
    2011-10-24 at 1:44 pm

    Online Article……

    [...]The information mentioned in the article are some of the best available [...]……

  • Free U Value Calculator says:
    2011-10-24 at 5:57 am

    Lost, Again…

    I do not have an idea about this story. None of it makes sense to me….

  • CIA Test Preparation says:
    2011-10-24 at 5:57 am

    Just Wonderful…

    That is just excellent….

  • bloomingdales furniture says:
    2011-10-24 at 2:35 am

    Read was interesting, stay in touch……

    [...]please visit the sites we follow, including this one, as it represents our picks from the web[...]……

  • cartier engagement rings says:
    2011-10-24 at 2:17 am

    Recent Blogroll Additions……

    [...]usually posts some very interesting stuff like this. If you’re new to this site[...]……

  • « Previous 1 ... 9 10 11

    Leave a Reply:

    Click here to cancel reply.

    Name (required):
    Mail (will not be published) (required):
    Website:
    Comment (required):
    XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>
    验证图片
    刷新验证码
    *

    Popular Articles

      • How to uninstall pc optimizer pro, pc optimizer pro removal 1139 comment(s)
      • what is Pbupdate.exe and how to fix Pbupdate.exe error? 1138 comment(s)

    latest comments

    • 正在加载...

    Tags

      Antivirus Suite Autorun ave.exe Backdoor Backdoor.Win32 Backdoor.Win32 removal browser home page was altered cc Clicker.dj Clunky Backdoor removal Default home page is modified DLL files error DOMDocument->load() downloader encountered Fix Kernel32 Dll Error MAC Microsoft Security Essentials PSW PSW.Kykymber.cc registry was modified remove MyWinLocker remove regedit32.exe remove safedrv.exe remove Trojan.Win32.Buzus.a Run command slow computer Speed Up Computer speed up pc Trojan Trojan-Downloader.Win32.Small.b removal Trojan-PSW.Win32 Trojan.Win32 Trojan.Win32 removal Trojan Downloader Trojan Dropper uninstall MyWinLocker variant dj Virus W32.Cervivec.A@mm Win32 Win32.Hack.GrayBird.al.761856 Win32.TrojDownloader.Guupk.ps Worm Worm.Win32

    Category

    • News
    • Others
    • Registry
    • Script
    • System Utility
    • Virus
    • Windows
    • XML

    Archives

    • December 2011
    • November 2011
    • October 2011
    • September 2011
    • July 2011
    • June 2011
    • May 2011
    • April 2011
    • March 2011
    • February 2011

    Links

    • Download Drivers

    Pages

    • Regtweaker
    • Spyware Cease
    
    Copyright © 2012 PC solutions. Powered by VersionHunter.com. registry repair |Threats Center
    Top