Trojan Downloader Removal Guide

Threat Level:
8/10
Rate this Article:
Comments (0)
Article Views: 26269
Category: Trojans

Trojan Downloader is a malicious Trojan program which is responsible for downloading and installing other malicious Trojans to your PC. It enters the system surreptitiously through bundling itself with other malware, as well as through bundling itself with third party security downloads and updates. It will not alert the user to its presence on the system, and performs all of its rubbish actions in the background of the system. This will contribute to making it much more difficult for the user to detect and remove Trojan Downloader from the system.

What makes Trojan Downloader even more dangerous is that it will connect to the Internet through HTTP without the user’s permission, and then proceed to make the PC more vulnerable to father attacks and more malware infiltrations and infections.

Trojan Downloader will also install keyloggers to your PC which will record your keystrokes, stealing your financial information and usernames and passwords. These include banking details, credit card numbers and other sensitive info.

This Trojan program operates under different names, and may be detected under various names including the following:

Trojan-Downloader.Win32.Delf.ain
Trojan-Downloader/W32.Small.152912
Win32.Banker Trojan.Downloader-34408
Mal/EncPk-DG
W32/PolySmall.BP!tr

Save yourself the trouble and effort and make use of the removal power of a powerful security tool in order to permanently destroy Trojan Downloader and restore your PC’s security. This is an investment in your PC’s security and will not only obliterate Trojan Downloader but also protect your system against similar attacks in future.

Download Remover for Trojan Downloader *
*SpyHunter scanner, published on this site, is intended to be used only as a detection tool. To use the removal functionality, you will need to purchase the full version of SpyHunter.

Trojan Downloader technical info for manual removal:

Files Modified/Created on the system:

# File Name File Size (Bytes) File Hash
1eeibpemw.dll86080 bytesMD5: c5ad86fbb398e3b8d7698ce9a5e52334
2jrgxanhg.dll84544 bytesMD5: 2d3b6e3f68ae848a5b7bd82add8db7ed
3movctrlswd.dll311296 bytesMD5: cbfddf3eae61f356089bd4fa262c4ad9
4CPpassword.exe470503 bytesMD5: a481147c1567d73b3736a82251785167
5swxuwjyv.dll80448 bytesMD5: 3102b0cb043c7b4d33567435647b3cbe
6duxp.exe78341 bytesMD5: d9f83ef353411236472345941d4a5e4e
7tnaoqkjj.dll81984 bytesMD5: a42e5a9a2bde83119c4df6d4be3a4ef6
8__c005F324.dll66052 bytesMD5: c25f593b5530bf2b2ae57bc863049886
9tool4.exe1024 bytes
10tudvusxt.dll85568 bytesMD5: 1107381211415a56c216352542bc4528
11nnnol.dll309344 bytesMD5: 91199f38f983f10c0272bec8deb1aee9
12eewoedyu.dll106496 bytesMD5: 482bca5b73faf432e72623e7e361f892
13nwnmff_7[1].exe32768 bytes
14pschdprf.exe35590 bytes
15yopjnbds.dll85056 bytesMD5: b1e877e75197f336e1b783b5a7090c43
16webofmsu.dll81472 bytesMD5: 6d356cce1a74d8b1805155ebf168ee57
17vshluep.exe46592 bytesMD5: 283a54a783896f8c94bca40292dbd1f3
18nkwglcqf.dll91712 bytesMD5: 88c87100ff81f30ed74d30836af37784
19bbhputir.dll79424 bytesMD5: 59cdf4ef13c588d78f2f7dfb441000fa
20ftbbydng.dll81472 bytesMD5: 2207f0fceb04358d425b50c3076b707f
21qiawpbjj.dll21504 bytesMD5: fe4e6b57d5b13ee330c471056aea32d0
22eniiaqjc.dll79936 bytesMD5: bd7f2f1fca2a34c18e71f74f29f58229
23prppjxrr.dll79424 bytesMD5: 2edfe97c6db793657ba0c405510c35e6
24the librarian solomons mine.exe112141 bytesMD5: 2e0089142d4a6eeeb9adc6641bebccef
25jkkjigf.dll13312 bytes
26raarvegn.dll81984 bytesMD5: 644201d09ae0551eda73a9cff5325514
27mc-0-0-0.exe77206 bytesMD5: 6b9e1479a7de17344efed6df5d69b322
281189461984[1].exe20992 bytesMD5: 83192052234b8cfc25a6fb7a96649037
29debgeecj.dll137728 bytesMD5: 3dfe0a14cce00d5799cc524e9302dde6
30bkodembw.dll91712 bytesMD5: 6469160c08dd06de022733cbc085a932
31mlksnxva.dll81472 bytesMD5: 4dcb5965f717893ce5a132a11aa5ad99
32jkokdhxq.dll79936 bytesMD5: acb1f87e812e222bc2763f6663f47ee0
33tool5.exe1024 bytes
34bkinuhyw.dll421888 bytesMD5: 923afcbca08a7bcd8cef11dcb957489b
35lgvruijd.dll84544 bytesMD5: be1470b3bee9d7b198cf4f122ac74a45
36ehalbvyy.dll76864 bytesMD5: 102271eb488f761739d5c373a57da3c3
37ibaihtxl.dll85568 bytesMD5: f4043ed90e0c047224816accf982d8a0
38toolbar.exe32128 bytesMD5: 5c33d977da7c7a767a11639376a8a1ba
39yjovpdko.dll85056 bytesMD5: 57dec796b95265fd4f44621f90871961
40wcmsynqr.dll124797 bytesMD5: 44b4544c43ba5efb06881c4c4375819f
41zyjirsxm.dll53248 bytesMD5: 7539b32428f77a420aaa2ed70893ca16
42vtkhylcg.dll91712 bytesMD5: 08fcb79e0edb4ac8170e9695eed6b03d
43vfyxlakl.dll80448 bytesMD5: 59e1845a0ae78c7707967c208ef0c61f
44issjsbud.dll84545 bytesMD5: cbe34589be2072fce298406ba29ab0fc
45ss245sd.exe208896 bytes
46mxrvcubc.dll85568 bytesMD5: 7ba19b70fd78715f9f142d1875ffdc1b
47cxoddtie.dll80960 bytesMD5: b5a80033019979086c5c530bb62720aa
48gacineon.exe135360 bytesMD5: 72e4a2a95b102f332cf1b56d7f67a53b
49zqtkvilo.dll57344 bytesMD5: 1b0de76441a4d2bbe30a4363f6a4c4da
50glwlnvmc.dll91712 bytesMD5: d21058fefc643161aa689da2a92f87a2
51ycnhftdl.dll84544 bytesMD5: af5596b52e7080f4de13fc206f6e9eaa
52dkwiligd.dll78912 bytesMD5: f88340b949525bbfe9ea14772a7d55b8
53nsu882.dll81920 bytesMD5: ea3e3e0a1022a3af207434c67d800857
54fxdodaab.dll85056 bytesMD5: 4ad94a7fbf2a4d8e947f1336ecf5ac29
55dmband.exe21504 bytes
56efxfuvqc.dll84544 bytesMD5: 1092b99e16c08363ecd19e51faa1f4dc
57khfgh.dll244832 bytesMD5: 081e6d728ad8aa4d56c1eae67ad58825
58KB_2874.tpk345 bytes
59Gwang.exe81920 bytes
60axvxxmwl.dll86080 bytesMD5: b2660fb8466737a15e02b94ea2aa26a4
61olddejdj.dll340032 bytesMD5: 297b816b980ba2ab1d545b3caad8f830
62drsihne.dll171520 bytesMD5: d4f17ebb09c83e65891141215d8ded6e
63laf1.exe15360 bytesMD5: 70cbe5a52541325d441f0a250a1ccea4
64yjsonyqa.dll85056 bytesMD5: 866af1b981c1c1a0c0f920806339e5d0
65blackbo.dll93184 bytesMD5: da09002276682df18e5aec4226306f73
66__c00A3D23.dat33856 bytesMD5: 15921705717795e3d347d960648a7755
67fxthowfl.dll84545 bytesMD5: 82e1fcc833cc02091c38c4e72b4f72d9
68ms1.exe3072 bytesMD5: af79de8a3240ddad3c7873d4bb094d0a
69cdm21521.exe94208 bytesMD5: 5056bb972454860970ce8978a3d1e151
70hutqpdvr.dll120852 bytesMD5: d6c536e94bc0fd9b43a83abe539adf53
71irhbpuia.dll85056 bytesMD5: 060e07cf876b38228288d5f55b001e3e
72Desktop.sysm78339 bytesMD5: 8e47a67630d5202a0b8798b6607c71ed
73_OUdescription.exe40960 bytesMD5: 50089277efd5ede6572e8c1ebe8a4e85
74vjnacnkj.exe43008 bytesMD5: 6a90c5066309c8aeef1786c8348c1489
75zoxboi.dll139264 bytesMD5: f08944879e6175a0de8f6541913c01d4
76kybrdff_7[1].exe86016 bytes
77auhigsge.dll86080 bytesMD5: b6133b943f011283e33e7cb9bd39af07
78rhzjxc.exe57344 bytesMD5: e37cb1e20ba8db50e572fc801d3c9e5e
79edtcw.dll155648 bytesMD5: b88f36ad1b0775aae6b7fca1c667032d
80mljul1.exe301568 bytesMD5: f266c493ef850e517a35ff79dc366012
81svchost.exe11776 bytesMD5: c48fdb464f48f9dc72858de1db0c1a18
82b124.exe207596 bytesMD5: 4c9ecfc80b5a7b024efd9ac1b781e124
83bhmyqlak.dll79936 bytesMD5: ce08fb2819981089174e24daeae87132
84cic.exe131104 bytes
85Dscp1.exe361833 bytesMD5: 5b8072ef176d214f8609e40505008d9b
86zopqjkto.exe54272 bytesMD5: 6f93421024aff41a46561c1f279b9887
87lwfmtjj.dll139264 bytesMD5: 5956f5d28e4b6b910d83f7e3d6d19e0d
88gm.exe61440 bytesMD5: 39bc09e4f3b9c5707cb4244e8b11c936
89ninsaryo.dll88128 bytesMD5: fd5c6a6d2fc9ea3d54c2b1ed4f20dafe
90movctrlnkd.dll286720 bytesMD5: 2ae7d4a12d29319363a29324de56a117
91ljjgffc.dll36352 bytes
92urqpn.dll305760 bytesMD5: 3a8cdd2e1388bc234db5a9e94c150dae
93{b91413db-d88a-a499-2661-f9f9441c9f46}.dll329216 bytesMD5: 8e118ebe8cc3ddea1f5920d5bd6b4489
94qtrqajuc.dll79936 bytesMD5: b8afa27aaceea61bbb44fd8e8c995872
95plite731.exe13824 bytesMD5: a66a71dbc13b2e0c646b0cd63df5bee4
96ehfvlgao.dll85056 bytesMD5: 357f45765a1e0248a03e5feea9a06e14
97sqkyaiio.dll79424 bytesMD5: e9f9aa52196dca0d4d5d2f62a848b685
98tool2.exe31447 bytes
99xecfrunh.dll151104 bytesMD5: 00b88f849888b340a4e0d82f8d1628a2
100kqdsrngj.exe53279 bytesMD5: cb7ad056f2ecd4a96bf0a2546f3414fc
101installer.exe166920 bytesMD5: 35860cf992543371bb559387d9d66462
102kl1.exe84480 bytes
103mspoolg.dll95408 bytes
104aamg.exe78337 bytesMD5: 09769bab9b1620c49b8f1c0993779b4d
105obafabyd.dll59904 bytesMD5: 5495968f17507e8d355a2ea50c02c6d5
106luhcfmjo.dll58880 bytesMD5: 5a16e065ba0db6fee223307338309bc6
107mscorsvc.exe16384 bytesMD5: 322dd6065cb1c6496d534e42ffecb2f8
108khfcdcy.dll44054 bytesMD5: 91ecfd3124ca508800178d6617b98ae9
109qiawpbjj.exe131592 bytesMD5: b0a3d898dedfeb666ba446dac6a6289e
110xjjqnrc.exe54784 bytesMD5: dd353708977dc36146d65c7caadeb191
111detyrsso.dll83520 bytesMD5: 6ee2a7c05efcde312a26e4b5429062d7
112kqvgxa.dll169984 bytesMD5: c146e241a5ec55232ae3aa4059a4e26e
113svchosts.exe36864 bytesMD5: 7b69c00ba9f072dd06d61411fc09ded5
114__c00C0CD.dat64725 bytesMD5: 0545294a912933a0e292c0850955d1ce
115spoolc.exe87552 bytesMD5: dd269e03ed85557e1fd7f9bd6d52adb7

Registry Modifications:

The following Registry Keys were created:

  • pschdprf.exe
  • 1103768a
  • cic
  • SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler {2C1CD3D7-86AC-4068-93BC-A02304B25319}
  • 78f2a073
  • vjnacnkj
  • ff1482e11692
  • 0053c070
  • dumprep
  • fabcvwpo
  • SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE AntiVir
  • SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE Windows Update
  • plite731
  • 7c970f2d
  • 68eb62da
  • 8c4187fe
  • 08a1bf1e
  • c8347858
  • SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCEEX AntiVir
  • rktqjqvq
  • 90f32b67
  • {0D-D4-40-0C-ZN}
  • SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCEEX msconfig
  • 5424edb5
  • 2629165f
  • SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad kopmet
  • e4e87def
  • d45a08da
  • amb1avl
  • 02e224b4
  • SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad DCOM Server 25319
  • 6887f700
  • ms
  • SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE Update Checker
  • 847a8a58
  • SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCEEX Update Checker
  • SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE msconfig
  • ms0653405-14619
  • 12ccff32
  • dwhcdglq
  • ss245sd
  • 3cc0d4a3
  • SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCEEX Windows Update
  • pschdprf
  • 6ca52554
  • cic.exe

Reply

Your email address will not be published.

Name
Website
Comment

Enter the numbers in the box to the right *