Sunday, October 25, 2009

How to Remove The Trojan Downloader?

The Trojan-Downloader is a kind of Trojan, which once running will generate infection files, modify Registry and add Startup items, in order to make itself run at the computer startup. Then, through network connection, Trojan-Downloader downloads a great number of Trojans which are able to run automatically. The downloaded Trojans then modify the associated files of .exe file, and disable exe file from normal function. Meanwhile, Trojan-Downloader is so stubborn that lots of antivirus software can do nothing to it. Or, even though it was reported to be removed successfully, you can still find it later.

If you are careful enough, you will find that after being activated, Trojan-Downloader will generate the files XXX.exe and XXX.dll in the directory %systemroot%\system32. Then, you can go to this directory and find out and delete these files. If they can't be removed, then they are possible the files run by Trojan-Downloader. In this case, you can try the following method: download a robust antispyware program to remove Trojan; start up your computer in safe mode (Press F8 at computer booting up); use the antispyware program in safe mode to detect and remove Trojan-Downloader, and after which please download the Registry repair tool to repair your system Registry and check the startup items.

Other Methods to Manually Fix the System Infected by Trojan-Download :

Go to C:\ WINDOWS\system32\drivers and find out the file X .sys. Open Spyware Cease, use the File Deletion function. Add the files needed to be deleted, and execute the forcible file deletion. (Note: The File Deletion function is very powerful and no file can be restored once deleted. So make sure the file name is correct. ) Find out Trojan-Download in C:\WINDOWS\system32, and delete it with the same method. Then, Start - Run - type regedit to open the Registry Editor, and delete the Registry keys of Trojan-Download from the following
HKEY_LOCAL_MACHINE\SYSTEM\Controlset001\Services HKEY_LOCAL_MACHINE\SYSTEM\Controlset002\Services HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services

http://www.spywarecease.comhttp://www.threatremove.com

Article Source: http://EzineArticles.com/?expert=Amy_Zhou

No comments: