• Home
  • Regtweaker
  • Subscribe to Posts
  • Subscribe to comments

PC solutions

Give you Professional Suggestions

  • Home
  • News
  • Registry
  • Script
  • System Utility
  • Virus
  • Windows
  • XML
Home Virus manually remove Trojan-Dropper.Win32.Ekafod.x

manually remove Trojan-Dropper.Win32.Ekafod.x

Posted on Saturday, 14 May 2011
105 Comments
Share|

virus Name: trojan-Dropper.Win32.Ekafod.x

Risk level: Medium

Virus Description

The virus disguised as a folder icon and Hide extension to confuse users, the virus primarily spread through the “file bundle”, “download tool to download”, “web page linked to horse”, etc., the viruses main purpose is to release the virus into the computer to run, the user Computer occurs after the system is running Slow, unknown process.

Infection in the operating system
Windows 2000/Windows XP / Windows 2003/Windows Vista / Windows 7

Transmission

Bundle file, web page linked to horse, download tool

Manually removal

1, manually delete the following files:
% Systemroot% \ System32 \ wicy111.dll
% Systemroot% \ System32 \ tt_b_2.dll
% Systemroot% \ System32 \ lockdrv.sys
2, manually delete the following Registry key:
HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ lockdrv.sys
3, manually modify the following registry key:
Modify the HKEY_CLASSES_ROOT \ CLSID \ {871C5380-42A0-1069-A2EA-08002B30309D} \ shell \ OpenHomePage \ Command
Name:
Data: C: \ Program Files \ Internet Explorer \ IEXPLORE.EXE

Variable declaration:

% SystemDriver% system where the partition, usually “C: \”
% SystemRoot% WINDODWS directory, usually “C: \ Windows”
% Documents and Settings% user file directory, usually “C: \ Documents and Settings”
% Temp% temp folder, usually “C: \ Documents and Settings \ current user name \ Local Settings \ Temp”
% ProgramFiles% system program the default installation directory, typically: “C: \ ProgramFiles”
Analysis of the virus

(1), find the existence of a computer “virus is the current directory \ virus name” (without the exe extension) directory, if it exists, that exists in the current directory and name of this virus in the same directory name, use Explorer to open. If you do not exist, set the registry key HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Advanced the corresponding key, hide file extensions, do not show hidden files and system protected files, so as to achieve the effect of the virus itself hidden.
(2), open the registry key HKEY_CLASSES_ROOT \ CLSID \ {871C5380-42A0-1069-A2EA-08002B30309D} \ shell \ OpenHomePage \ Command, change the default key is “C: \ Program Files \ Internet Explorer \ IEXPLORE.EXE http : / / www.488 **. cn “.
(3), to find whether there is% Systemroot% \ System32 \ wicy111.dll and% Systemroot% \ System32 \ tt_b_2.dll, if not then create two files, and write corresponding data to create processes were up by running the command regsvr32 These two dll files.
(4), create% Systemroot% \ System32 \ lockdrv.sys, and writes the data to determine whether there lockdrv.sys service, if not then create the appropriate services for this file (the service-driven process, the type of service, services. msc query not only view in the registry), and create a corresponding service registry key HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Services \ lockdrv.sys, then start the service.
(5), in the current directory to create a batch virus program 375519961057540.bat, and inside write a batch command. Run this command to delete the virus file and the batch process.
(6), loaded to run% Systemroot% \ System32 \ wicy111.dll, in the registry key HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ SharedTaskScheduler key items created {C4560D12-CE25-4A2E-A5D4-B5070FCBE282} , the value csiddll.
(7), check whether the computer can access the Internet if you can, will and http://www.renren125 **. com / MainDll / SoftSize.asp a link. Download Trojan virus to the local operation.

Virus to create  files:

% Systemroot% \ System32 \ wicy111.dll
% Systemroot% \ System32 \ tt_b_2.dll
% Systemroot% \ System32 \ lockdrv.sys
Virus current directory \ 375519961057540.bat


Share this Post:
Digg Google Bookmarks reddit Mixx StumbleUpon Technorati Yahoo! Buzz DesignFloat Delicious BlinkList Furl
Tagged with: Trojan, Trojan Dropper, Trojan-Dropper.Win32.Ekafod.x removal

105 Responses to “manually remove Trojan-Dropper.Win32.Ekafod.x”

Trackbacks are disabled.

Kiteboarding Questions
how to care for puppy
second hand cars
what do avon representatives do
siker
Transparent Film
Plumbing Fairfax VA
Cheap Bed Delivery
public relations firm
workout to lose man boobs
grasscloth wallpaper ideas
halifax painters
tyskland ekonomi
fetma
wolverine streaming
how to get friends on facebook
acne and treatment
billigt flyg amsterdam
guld köpa ädelmetaller
paris disneyland
donne nude
landscaping ideas
jobs in gov
Carpet Cleaning Milford
Air Zenyth
holiday rentals
Carpet Cleaning RI
Make Money Online
Spy watch
the Best Workout Dvd
Companies News
p90x diet
recipes mac and cheese
Transparent Film
Ripstik Caster Board
Nike Jordan 5
hyip monitor
investment property melbourne
understanding preexisting conditions and medicare
rockface Gem Hematite
Cheap Wireless Printers
aluminium windows
aluminium windows
investment property in melbourne
Burberry Bikinis
How To Get Bigger Breasts
auto warranty reviews
megaupload
save auto insurance
  • how much is my car worth says:
    2011-10-25 at 1:01 pm

    Its hard to find good help…

    I am forever proclaiming that its hard to get quality help, but here is…

  • Oyun Oyna says:
    2011-10-15 at 7:15 pm

    istanbul evden eve nakliyat…

    Bakirköy evden eve nakliyat…

  • backlinkler says:
    2011-10-14 at 12:27 am

    backlinkler…

    backlinkler.com…

  • görüntülü sohbet says:
    2011-10-13 at 9:46 pm

    kameralı sohbet…

    kameralı chat…

  • Ucuz Uçak Bileti says:
    2011-10-12 at 9:48 pm

    uçak bileti al…

    Ucuz Uçak Bileti…

  • kayseri havaalanı araç kiralama says:
    2011-10-12 at 2:01 pm

    kapadokya rent a car…

    nevşehir rent a car…

  • « Previous 1 2

    Leave a Reply:

    Click here to cancel reply.

    Name (required):
    Mail (will not be published) (required):
    Website:
    Comment (required):
    XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>
    验证图片
    刷新验证码
    *

    Popular Articles

      • How to uninstall pc optimizer pro, pc optimizer pro removal 1139 comment(s)
      • what is Pbupdate.exe and how to fix Pbupdate.exe error? 1138 comment(s)

    latest comments

    • 正在加载...

    Tags

      Antivirus Suite Autorun ave.exe Backdoor Backdoor.Win32 Backdoor.Win32 removal browser home page was altered cc Clicker.dj Clunky Backdoor removal Default home page is modified DLL files error DOMDocument->load() downloader encountered Fix Kernel32 Dll Error MAC Microsoft Security Essentials PSW PSW.Kykymber.cc registry was modified remove MyWinLocker remove regedit32.exe remove safedrv.exe remove Trojan.Win32.Buzus.a Run command slow computer Speed Up Computer speed up pc Trojan Trojan-Downloader.Win32.Small.b removal Trojan-PSW.Win32 Trojan.Win32 Trojan.Win32 removal Trojan Downloader Trojan Dropper uninstall MyWinLocker variant dj Virus W32.Cervivec.A@mm Win32 Win32.Hack.GrayBird.al.761856 Win32.TrojDownloader.Guupk.ps Worm Worm.Win32

    Category

    • News
    • Others
    • Registry
    • Script
    • System Utility
    • Virus
    • Windows
    • XML

    Archives

    • December 2011
    • November 2011
    • October 2011
    • September 2011
    • July 2011
    • June 2011
    • May 2011
    • April 2011
    • March 2011
    • February 2011

    Links

    • Download Drivers

    Pages

    • Regtweaker
    • Spyware Cease
    
    Copyright © 2012 PC solutions. Powered by VersionHunter.com. registry repair |Threats Center
    Top