Click on screenshot to zoom
Danger level 8
Type: Trojans
Common infection symptoms:
  • Connects to the internet without permission
  • Shows commercial adverts
  • Slow internet connection
  • System crashes
  • Annoying Pop-up's
  • Slow Computer

Trojan.Ertfor

If you have heard the Greek legend of a Trojan Horse, you will understand how cleverly the sinister Trojan.Ertfor can trick hundreds if not thousands PC users all around the globe. The malicious program can easily slither into your computer, without being detected, hide from existing Windows security tools, download even more malware, and attack a Windows user in a sudden and unexpected manner. Trojan.Ertfor is not a new invention, and its creators have had enough experience, implementing this and many previous Trojans, in order to profit and spread infections, which can easily remove Windows privileges, destroy data and turn PCs into useless metal boxes.

It is true that Trojan.Ertfor is a master of disguise, a truly “invisible enemy”; nonetheless, it does not mean that it should be dismissed and ignored, because it can cause more damage than you would ever want for your personal safety or your computer! The easiest way to realize that Trojan.Ertfor is in deed running its processes, in the background of your system, is by noticing minor system changes and malfunctions, which soon enough can turn into really big problems. A few signs of Trojan.Ertfor’s activity is removed access to Windows components, like Registry Editor or Task Manager, deleted files, terminated processes, activity of unfamiliar programs, other malware, disabled activity of security tools, missing system’s scheduled updates, etc. These Trojan.Ertfor dysfunctions should be clearly noticeable, because of your inability to run Windows normally; however, there are those Trojan.Ertfor-caused symptoms, which you will not be able to note, but which can cause irreversible damage. Most importantly, Trojan.Ertfor’s components are responsible for connecting to remote servers and Internet, without any of your consent, which can result in the usage of your emails addresses, phone book contacts for malicious spreading of Trojan.Ertfor!

Trojan.Ertfor is a cunning cyber criminals’ tool, which can use your accounts not only for mere financial profit, but also to pin your name to unlawful schemes. If you do not want to become an important schemers’ instrument, and you suspect Trojan.Ertfor’s existence in your operating Windows system, install antispyware tools right away! Only these implementations will remove Trojan.Ertfor from your operating system and will help you to return to your normal Windows life.

Download Spyware Removal Tool to Remove* Trojan.Ertfor
  • Quick & tested solution for Trojan.Ertfor removal.
  • 100% Free Scan for Windows
disclaimer

How to manually remove Trojan.Ertfor

Files associated with Trojan.Ertfor infection:

z9u4q1hco0e3.exe
winlogon.exe
winamp.exe
win32.exe
win16 .exe
win.exe
user.exe
svchost.exe
spoolsv.exe
smss.exe
setup.exe
services.exe
rvzyhjs840.exe
nvsvc32.exe
msmgm.exe
mmagootl.dll
mdm.exe
lsass.exe
kcpyle8ibb7.exe
jmcf97objs518wb.exe
iexplarer.exe
hexdump.exe
gdi32.exe
drweb.exe
csrss.exe
avp32.exe
avp.exe
3524351346.exe
3474095969.exe
3141634129.exe
2911240575.exe
2371523507.exe
1943180492.exe
1046314817.exe
Winservice.exe
sysedit.exe
login.exe
cmd.exe
hdxjd4g.dll
ykb9u.dll
apgu9l5kx2.dll
m5u79tslq.dll
kub7mri7u.dll
a9n05zgh1k.dll
hpaq.exe
grjbuccd30.exe
tjfy1.exe
cel5k.dll
qgw62tomlq.dll
c74ox1.dll
dxveefu.dll
ynd6o.exe
lzug6.exe
ejuu6mbl0.dll
cmambd8.exe
f0mgt58.exe
fnrwvfsoy.dll
yiml8ea7fw.dll
w6zgnaq38i.dll
lawyit.dll
grffr83hn.dll
winlogen.exe
hs7f3uhduhfukde.dll
x5l2o9osi.exe
sdjee3inf.dll
hjs398iddi.dll
jkww73nf9834j.exe
mdx7jc83.exe
had732ufn8.dll
z2g42b.exe
g6sjfdy83hn.dll
ewcs73nf.exe
test1[1].exe
jkshfuiehi.dll
afnoinkdsfe.dll
pgg8x6.dll
nzt04jg.dll
efw42e.dll
ygsuhdf83id.dll
tajf83ikdmf.dll
winlogqn.exe
sdcvddd.dll
feo71pjc65.exe
nhser43uhjnefr.dll
kjr3iorojdnbfi43unjfd.dll
hs78344kjkfd.dll
rsekd83jde.dll
kdfgj83ke.dll
djki397g.dll
hgfdge4unjdfdg.dll
rakmdlkd83indfgnbu.dll
jkse73hedfdgf.dll
hsef73uhef.dll
winlogun.exe
gjm86akm34.dll
Kf9467g.dll
jfiehayd.dll
f9ssyypbuw.exe
gsf83iujid.dll
q041wz8.exe
winlognn.exe
tehfb873inf.dll
hsfi3ujndf.dll
rwhbfb873unjdfdg.dll
winlogin.exe
winloggn.exe
jsne87fidgf.dll
siejf93.dll
js783hffgf.dll
jkdf8ji3efd.dll
winlogan.exe
zvqeg03p.exe
yaubfh983ind.dll
zfgh83jg3.dll
c00j3.exe
x95a5wgnq0.exe
hx9ui4v.exe
hsf73ikmdf3f.dll
a6gt9v9.exe
sdfadccddkn93.dll
hsari3jndsbfi73.dll

Trojan.Ertfor DLL's to remove:

mmagootl.dll
hdxjd4g.dll
ykb9u.dll
apgu9l5kx2.dll
m5u79tslq.dll
kub7mri7u.dll
a9n05zgh1k.dll
cel5k.dll
qgw62tomlq.dll
c74ox1.dll
dxveefu.dll
ejuu6mbl0.dll
fnrwvfsoy.dll
yiml8ea7fw.dll
w6zgnaq38i.dll
lawyit.dll
grffr83hn.dll
hs7f3uhduhfukde.dll
sdjee3inf.dll
hjs398iddi.dll
had732ufn8.dll
g6sjfdy83hn.dll
jkshfuiehi.dll
afnoinkdsfe.dll
pgg8x6.dll
nzt04jg.dll
efw42e.dll
ygsuhdf83id.dll
tajf83ikdmf.dll
sdcvddd.dll
nhser43uhjnefr.dll
kjr3iorojdnbfi43unjfd.dll
hs78344kjkfd.dll
rsekd83jde.dll
kdfgj83ke.dll
djki397g.dll
hgfdge4unjdfdg.dll
rakmdlkd83indfgnbu.dll
jkse73hedfdgf.dll
hsef73uhef.dll
gjm86akm34.dll
Kf9467g.dll
jfiehayd.dll
gsf83iujid.dll
tehfb873inf.dll
hsfi3ujndf.dll
rwhbfb873unjdfdg.dll
jsne87fidgf.dll
siejf93.dll
js783hffgf.dll
jkdf8ji3efd.dll
yaubfh983ind.dll
zfgh83jg3.dll
hsf73ikmdf3f.dll
sdfadccddkn93.dll
hsari3jndsbfi73.dll

Trojan.Ertfor processes to kill:

z9u4q1hco0e3.exe
winlogon.exe
winamp.exe
win32.exe
win16 .exe
win.exe
user.exe
svchost.exe
spoolsv.exe
smss.exe
setup.exe
services.exe
rvzyhjs840.exe
nvsvc32.exe
msmgm.exe
mdm.exe
lsass.exe
kcpyle8ibb7.exe
jmcf97objs518wb.exe
iexplarer.exe
hexdump.exe
gdi32.exe
drweb.exe
csrss.exe
avp32.exe
avp.exe
3524351346.exe
3474095969.exe
3141634129.exe
2911240575.exe
2371523507.exe
1943180492.exe
1046314817.exe
Winservice.exe
sysedit.exe
login.exe
cmd.exe
hpaq.exe
grjbuccd30.exe
tjfy1.exe
ynd6o.exe
lzug6.exe
cmambd8.exe
f0mgt58.exe
winlogen.exe
x5l2o9osi.exe
jkww73nf9834j.exe
mdx7jc83.exe
z2g42b.exe
ewcs73nf.exe
test1[1].exe
winlogqn.exe
feo71pjc65.exe
winlogun.exe
f9ssyypbuw.exe
q041wz8.exe
winlognn.exe
winlogin.exe
winloggn.exe
winlogan.exe
zvqeg03p.exe
c00j3.exe
x95a5wgnq0.exe
hx9ui4v.exe
a6gt9v9.exe

Remove Trojan.Ertfor registry entries:

HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ sefjhf98jfoidsfoishgoiusgdgfgd
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ uishf9wuifwuh387fh3wufinhjfdwefe
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Windows Resurections
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ ygua8e7yhuiesfha876yfauy8fe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser HelperObjects\{A2234B15-23F2-42AD-F4E4-00AAC39C0004}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser HelperObjects\{A3BA40A2-74F0-42BD-F434-00B15A2C8953}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser HelperObjects\{b2c7b2a1-00f3-42bd-f434-00aaba2c8952}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser HelperObjects\{B45A4B16-23F2-41AD-F4E4-00AAC39C0004}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser HelperObjects\{BD56A320-23F2-42AD-F4E4-00AAC39CAA53}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser HelperObjects\{BF56A325-23F2-42AD-F4E4-00AAC39CAA53}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser HelperObjects\{D76AB2A1-00F3-42BD-F434-00BBC39C8953}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{A249BC15-23F2-42AD-F4E4-00AAC39C0004}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{A2BA40A0-74F1-52BD-F411-00B15A2C8953}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{A3BA40A2-74F0-42BD-F434-00B15A2C8953}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{A3BA40A2-74F1-52BD-F434-00B15A2C8953}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{A45A4B15-23F2-42AD-F4E4-00AAC39C0004}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{A5BF49A2-94F1-42BD-F434-3604812C807D}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{A6C7B2A1-00F3-42BD-F434-00AABA2C8953}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{B2C7B2A1-00F3-42BD-F434-00AABA2C8952}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{B5AF0562-94F3-42BD-F434-2604812C797D}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{BA603215-23F2-42AD-F4E4-00AAC39CAA53}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{BD56A320-23F2-42AD-F4E4-00AAC39CAA53}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{BF56A325-23F2-42AD-F4E4-00AAC39CAA53}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{C2BA40A1-74F3-42BD-F434-12345A2C8953}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{C2BA40A2-74F3-42BD-F434-2604812C8954}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{C2BA40A2-75F1-51BD-F413-04B15A2C8950}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{C5AF42A2-94F3-42BD-F434-3604812C897D}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{C5AF42A3-94F3-42BD-F434-3604832C897D}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{C5AF42A3-94F3-42BD-F634-3604832C897D}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{C5AF49A2-94F3-42BD-F434-2604812C897D}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{C5AF49A2-94F3-42BD-F434-3604812C897D}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{C5B24B16-23F2-41AD-F4E4-00ABC39C0004}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{C5BF40A2-94F3-42BD-F434-1604812C8955}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{C5BF49A2-94F3-42BD-F434-3604812C8955}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{C5BF49A2-94F3-42BD-F434-3604812C897D}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{C7BA40A1-74F2-52BD-F411-04B15A2C8953}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{D5BF4552-94F1-42BD-F434-3604812C807D}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{D5BF49A0-94F3-52BD-F434-3604812C8955}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{D5BF49A2-94F1-42BD-F434-3604812C807D}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{D76AB2A1-00F3-42BD-F434-00BBC39C8953}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ a783nfo9ewofmdejgywf
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ jdgf894jrghoiiskd
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ jsf8j34rgfght
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ jsf8uiw3jnjgffght
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ jsg8jfgfdfhfhf
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ kjahrfoi37rljanfaw3il7fhjd3f
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ ksjf93orkekfniw73nfdd
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ lrijh8s73jhbfgfd
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ xsgds4fgffght
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ xsjfn83jkemfofght
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5AF42A3-94F3-42BD-F634-0604832C897D}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A6C7B2A1-00F3-42BD-F434-00AABA2C8953}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B2BA40A2-74F3-42BD-F434-2604812C8954}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C2BA40A1-74F3-42BD-F434-12345A2C8953}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C6C7B2A1-00F3-42BD-F434-00AABA2C8953}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D5BF4552-94F1-42BD-F434-3604812C807D}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D5BF49A0-94F3-42BD-F434-3604812C8955}
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D5BF49A0-94F3-52BD-F434-3604812C8955}
Microsoft\Windows\CurrentVersion\Run\uidenhiufgsduiazghs
RUNNING PROGRAM\Explorer.EXE
RUNNING PROGRAM\f0mgt58.exe
RUNNING PROGRAM\grjbuccd30.exe
RUNNING PROGRAM\hpaq.exe
RUNNING PROGRAM\tjfy1.exe
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{A6C7B2A1-00F3-42BD-F434-00AABA2C8953}
{A6C7B2A1-00F3-42BD-F434-00AABA2C8953}
Disclaimer

Comments

  1. delci May 25, 2010

    winlogen.exe

Post comment — WE NEED YOUR OPINION!

Comment:
Name:
Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.