Click on screenshot to zoom
Danger level 9
Type: Trojans
Common infection symptoms:
  • Annoying Pop-up's
  • Block exe files from running
  • Blocks internet connection
  • Changes background
  • Connects to the internet without permission
  • Installs itself without permissions
  • Shows commercial adverts
  • Slow Computer
  • Slow internet connection
  • System crashes
Other mutations known as:

Trojan.VB

Trojan.VB is an umbrella name for such malignant infections as Trojan.VB.ews, Trojan.VB.joc, Trojan.VB.jwj, Trojan.VB.cpy and Trojan.VB.AFV. Some Windows users may also know the infection by such alias names as Backdoor:Win32/IRCbot, Trojan:Win32/Malat and Worm:Win32/VB.AM. Do not feel overwhelmed by the different names, because all of them identify the same infection within your operating Windows system. It has been found out that Trojans, worms and other malignant applications from this faction may use an abundance of different security vulnerabilities. Your PC could get infected via spam email attachments, bundled/encrypted downloads, infected USB drives, social engineering scams, etc. This is what has helped schemers to infect thousands of Windows systems already, and if you do not want to become another victim – delete Trojan.VB and learn how to do it using the material presented.

Such malicious files as 5dad2.exe, 736si.exe and 8F-bTxv.dll are common with Trojan.VB infections. Nonetheless, most malicious files (e.g. XP.exe) are not as explicit and will be much more difficult to detect and delete. One of the most dangerous files you need to be aware of is aecces.exe, because it can remove access to the Registry Editor and Task Manager, which are necessary to have Trojan.VB deleted. The malign executable can also disrupt Windows Security Center running, reconfigure the Registry and employ rootkits to hide devious processes from your recognition. Cmd.exe is the second threat as it can employ msmsgs.exe to steal your login data and use it to access Outlook and chat accounts, which cyber criminals could use for Trojan’s propagation to other systems. This is not all, as explorer.exe can download rogue antispywares, release fictitious security notifications and infect USB drives so that attached removable devices could be employed for malware distribution. As a matter of fact, tens of malignant cloaked files, including server.exe, svchost.exe or rundll32.exe, could be used to infect your PC with different Trojan.VB forms. Regardless, all of them need to be removed at once.

It is more than unlikely that Windows users inexperienced with malware removal will be able to overcome the difficulties created by rootkit components or cloaked executables. Therefore, it is not recommended to proceed manually if you are not sure how to delete Trojan.VB using the manual technique. As an alternative, you should trust automatic removal application SpyHunter that will remove the malicious program and will guard your Windows system in the future.

Download Spyware Removal Tool to Remove* Trojan.VB
  • Quick & tested solution for Trojan.VB removal.
  • 100% Free Scan for Windows
disclaimer

How to manually remove Trojan.VB

Files associated with Trojan.VB infection:

svcchost.exe
2465de9bcdd94be.exe
Student.exe
RAVCpl32.exe
i1eaavmm.exe
ScanDisc.exe
aadrive32.exe
TimeSync.exe
ipsec.sys
nsn13B.exe
netbt.sys
fa78.dll
dfsc.sys
.exe
WinDefender.exe
Wiscr.exe
puma.sys
MSN_WebCamSpy.exe
administration.exe
msmsgs.exe
vio.exe
system.exe
lsq.exe
jikd.exe
biv.exe
svflooje.exe
Saberz.r01.exe
javaupdater.exe
Clownfish.exe
oulwsvm.exe
regsvc32.exe
WLAcol.dll
iapadWMA.dll
0.18647449043215647.exe
0filsys.bin.exe
smsTx.exe
picture.scr
securitymanager.exe
Aszgzg.exe
7eb2eee8.dll
XoftSpySE.exe
WinRAR.exe
svc2dll.exe
mog.exe
KillProcessSetup.exe
kbmovm.dll
IlvMoney1105.sys
bfpc9.dll
bbprint.exe
8F-bTxv.dll
Flash_Player.exe
Vknt.exe
scanquery.dll
kbdjpn32.exe
clipsrv.exe
svsht2.exe
svsht.exe
mqq5aq.exe
o8l6go.exe
jmhqu.exe
jizz.exe
hmhfr.exe
aj20.exe
2ubrc.exe
2qb9w.exe
0ymn.exe
y69066.exe
xc3hh4.exe
fz77q.exe
acxw.exe
736si.exe
4jbpm.exe
3wf5d.exe
22wwk.exe
1jaxe3.exe
0kfp.exe
gtp3.exe
Cain.exe
avdv.exe
sysp.cpl
resultbar143.exe
GoogleUpdateBeta.exe
AntiVirus AntiSpyware.exe
svngage.exe
resultbrowser119.exe
questresult121.exe
dn.exe
zat5.exe
msible.dll
csrss.exe.exe
TXP.exe
riitd.exe
m.2AE68.tmp.exe
msmon.exe
msado320.tlb
IVV.exe
wins.exe
USBGuard.exe
rufbvrsc.exe
rpchttp32.exe
PCFix.exe
Modulo.exe
m.218.tmp.exe
chicken_invaders_4_plus8.exe
chicken_invaders_4_plus5_trainer.exe
advserv.exe
Uneraser_Setup.exe
UsbCheck.exe
Spoolvmx.exe
qPGLAEI.dll
LaunchChainz.exe
iconcs177016015.exe
d697a702.dll
bitutil.exe
access[2].exe
-e-2rrGtm__9I.dll
dtshldlp.exe
MWSBAR.DLL
qtfcyyp.exe
svcnost.exe
MediaCoder-0.7.2.4582.exe
ComboFix.exe
umdmgr.exe
sborka_blackmanos_13_69.exe
LEX.exe
gfWFwzSCBSga.exe
8bq9.exe
StartUp.exe
mscfg32.exe
LGxJuggkBGegHQ.exe
drm.exe
VRT1.tmp
sysr.cpl
sngrrm.exe
d3dlib.exe
aecces.exe
pleneWl.dll
patchcore716pe0.exe
crqytiqlajb.exe
AntiVirus_System_2011.exe
zlxfmompe.exe
NlsData000d32.exe
aHvFmtjxlhgIe.exe
audio.exe
andy133.exe
javachelper.dll
msnmsgra.exe
winb.exe
adtech2005.exe
lpcywinp.exe
ntsmod.exe
CLADD
SVchst.exe
WindowsUpdate.exe
w3e4r5t6yy8i.exe
mscj.exe
IExplorer.txt
a.exe
InstallMon.exe
srsyzygo.dll
%WINDIR%/system32/ddccs/svchost.exe
syroseop.dll
Audi0.exe
c9mgr.exe
namimgr.exe
wismgr.exe
binternet.exe
blosmgr.exe
umxmgr.exe
bjmbmgr.exe
mac.exe
scon.exe
MINE.exe
winde32.exe
bands.exe
eclindne.dll
rundll32.exe
5dad2.exe
Localhost.exe
Mga Dokumento.exe
prunnet.exe
DisTM.exe
snsrvc32.exe
nvscv32.exe
dewin32.exe
USB GATE.exe
ctfmon.exe
OPR.exe
winlogon.exe
prun.exe
wd[1].exe
CalcImpSAT[1].exe
wndrive32.exe
inandrom.dll
cmd.exe
alg.exe
wilogon.exe
winxp.exe
hostplug.exe
lssas.exe
svchost.exe
syre32.exe
geurge.exe
bill103.exe
msnmsgr.exe
TT.exe
MPTols.exe
nsvsc32.exe
winayuda.exe
net.net
Scvhosts.exe
Server.exe
XP.exe
csrss.exe
Test_123.exe
winlogon32.exe
geindigo.dll
sesingul.dll
brconcho.dll
apkruisi.dll
lspolysp.dll
4020.EXE
services.exe
lsass.exe
winfiles.exe
explorer.exe
dldesmos.dll
Explorer.pif
temp2.exe
rpc.exe
msiupdate.exe
A__MYDOCU~1[1].exe
Windows Explorer.exe
My Documents.exe
Copy of My Documents.exe
Athan.exe
swcupdate.exe

Trojan.VB DLL's to remove:

fa78.dll
WLAcol.dll
iapadWMA.dll
7eb2eee8.dll
kbmovm.dll
bfpc9.dll
8F-bTxv.dll
scanquery.dll
msible.dll
qPGLAEI.dll
d697a702.dll
-e-2rrGtm__9I.dll
MWSBAR.DLL
pleneWl.dll
javachelper.dll
srsyzygo.dll
syroseop.dll
eclindne.dll
inandrom.dll
geindigo.dll
sesingul.dll
brconcho.dll
apkruisi.dll
lspolysp.dll
dldesmos.dll

Trojan.VB processes to kill:

svcchost.exe
2465de9bcdd94be.exe
Student.exe
RAVCpl32.exe
i1eaavmm.exe
ScanDisc.exe
aadrive32.exe
TimeSync.exe
nsn13B.exe
.exe
WinDefender.exe
Wiscr.exe
MSN_WebCamSpy.exe
administration.exe
msmsgs.exe
vio.exe
system.exe
lsq.exe
jikd.exe
biv.exe
svflooje.exe
Saberz.r01.exe
javaupdater.exe
Clownfish.exe
oulwsvm.exe
regsvc32.exe
0.18647449043215647.exe
0filsys.bin.exe
smsTx.exe
securitymanager.exe
Aszgzg.exe
XoftSpySE.exe
WinRAR.exe
svc2dll.exe
mog.exe
KillProcessSetup.exe
bbprint.exe
Flash_Player.exe
Vknt.exe
kbdjpn32.exe
clipsrv.exe
svsht2.exe
svsht.exe
mqq5aq.exe
o8l6go.exe
jmhqu.exe
jizz.exe
hmhfr.exe
aj20.exe
2ubrc.exe
2qb9w.exe
0ymn.exe
y69066.exe
xc3hh4.exe
fz77q.exe
acxw.exe
736si.exe
4jbpm.exe
3wf5d.exe
22wwk.exe
1jaxe3.exe
0kfp.exe
gtp3.exe
Cain.exe
avdv.exe
resultbar143.exe
GoogleUpdateBeta.exe
AntiVirus AntiSpyware.exe
svngage.exe
resultbrowser119.exe
questresult121.exe
dn.exe
zat5.exe
csrss.exe.exe
TXP.exe
riitd.exe
m.2AE68.tmp.exe
msmon.exe
IVV.exe
wins.exe
USBGuard.exe
rufbvrsc.exe
rpchttp32.exe
PCFix.exe
Modulo.exe
m.218.tmp.exe
chicken_invaders_4_plus8.exe
chicken_invaders_4_plus5_trainer.exe
advserv.exe
Uneraser_Setup.exe
UsbCheck.exe
Spoolvmx.exe
LaunchChainz.exe
iconcs177016015.exe
bitutil.exe
access[2].exe
dtshldlp.exe
qtfcyyp.exe
svcnost.exe
MediaCoder-0.7.2.4582.exe
ComboFix.exe
umdmgr.exe
sborka_blackmanos_13_69.exe
LEX.exe
gfWFwzSCBSga.exe
8bq9.exe
StartUp.exe
mscfg32.exe
LGxJuggkBGegHQ.exe
drm.exe
sngrrm.exe
d3dlib.exe
aecces.exe
patchcore716pe0.exe
crqytiqlajb.exe
AntiVirus_System_2011.exe
zlxfmompe.exe
NlsData000d32.exe
aHvFmtjxlhgIe.exe
audio.exe
andy133.exe
msnmsgra.exe
winb.exe
adtech2005.exe
lpcywinp.exe
ntsmod.exe
SVchst.exe
WindowsUpdate.exe
w3e4r5t6yy8i.exe
mscj.exe
a.exe
InstallMon.exe
%WINDIR%/system32/ddccs/svchost.exe
Audi0.exe
c9mgr.exe
namimgr.exe
wismgr.exe
binternet.exe
blosmgr.exe
umxmgr.exe
bjmbmgr.exe
mac.exe
scon.exe
MINE.exe
winde32.exe
bands.exe
rundll32.exe
5dad2.exe
Localhost.exe
Mga Dokumento.exe
prunnet.exe
DisTM.exe
snsrvc32.exe
nvscv32.exe
dewin32.exe
USB GATE.exe
ctfmon.exe
OPR.exe
winlogon.exe
prun.exe
wd[1].exe
CalcImpSAT[1].exe
wndrive32.exe
cmd.exe
alg.exe
wilogon.exe
winxp.exe
hostplug.exe
lssas.exe
svchost.exe
syre32.exe
geurge.exe
bill103.exe
msnmsgr.exe
TT.exe
MPTols.exe
nsvsc32.exe
winayuda.exe
Scvhosts.exe
Server.exe
XP.exe
csrss.exe
Test_123.exe
winlogon32.exe
4020.EXE
services.exe
lsass.exe
winfiles.exe
explorer.exe
temp2.exe
rpc.exe
msiupdate.exe
A__MYDOCU~1[1].exe
Windows Explorer.exe
My Documents.exe
Copy of My Documents.exe
Athan.exe
swcupdate.exe

Remove Trojan.VB registry entries:

HKEY_CURRENT_USERSOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN Local security authentication server
HKEY_CURRENT_USERSOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN Yahoo Messengger
HKEY_CURRENT_USERSOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUNWindows Logon Applicationedc
HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerSharedTaskScheduler{46C82107-C059-4B5A-8BEE-361B06DB044C}
HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerSharedTaskScheduler{6742CC3A-65E8-4ED9-B051-AA119195C7BE}
HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerSharedTaskScheduler{7B618C0C-8D13-4F49-8559-BE04DC96899C}
HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerSharedTaskScheduler{96F7F230-8ADE-4930-A88F-3547C6A30BFF}
HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerSharedTaskScheduler{98A60C8C-2568-4029-9FB2-F2ED7E2DA8E8}
HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerSharedTaskScheduler{C94138D5-BED4-4865-9DD5-4F9955277EB0}
HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerSharedTaskScheduler{E30D4ED9-0D46-4757-ADE5-1736BEFCC15A}
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN %s
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN AntiMW
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN Athan
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN ayuda
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN DisTM
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN Dmbksf
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN ewrgetuj
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN Explorer
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN GoogleUpdate
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN Host Process for Windows Services
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN hostplug
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN Internet Explorer
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN media
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN Microsoft
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN Microsoft Driver Setup
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN Microsoft Error Reporting
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN MicrosoftNAPC
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN MSN
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN MSWUpdate
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN net
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN prunnet
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN regdiit
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN s%s
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN Scheluder
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN syre32
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN sysfbtray
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN System File
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN Test_123
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN USB GATE
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN windebug
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN Windows DLL Driver
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN Windows Firewall
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN Windows Live Conctacts Get
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN Windows Log Agent
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN Windows Logon Applicationedc
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN Windows RPC Service
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN WinNT 32
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN winserver
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN WinsysMon
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN ÿÿÿnvscv32.exe
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUNadtech2005
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUNntsmod
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUNOPR
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSNTCURRENTVERSIONWINLOGONUSERINIT userinit
MICROSOFTWINDOWSCURRENTVERSIONRUN*svchostBoot
MICROSOFTWINDOWSCURRENTVERSIONRUNprunnet
RUNNING PROGRAMctfmon.exe
RUNNING PROGRAMexplorer.exe
RUNNING PROGRAMServer.exe
Disclaimer

Post comment — WE NEED YOUR OPINION!

Comment:
Name:
Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.