如何清洗和去除Trojan.Win32.Obfuscated.gx、Trojan.Win32.agent.akk、Trojan.Zlob和等。
系统常数提示“关键系统错误!” 突然出现消息认为“您的浏览器由Trojan.Win32.Obfuscated.gx传染。 您在其他案件需要立刻清洗它可以很快被碰撞的您的系统,! 点击OK下载高技术antispyware保护软件! (推荐)”。 流行音乐在网页在Windows Explorer时任意地出现,例如,当打开URL使用IE,点击在一个链接或点击在一个文件项目。
如果被传染的用户`’点击好按钮下载高技术antispyware去膜剂,以文件名字作为防御者install.exe将提供一可执行。 在旁边, Google,雅虎! 并且窗口活查寻结果也许也被劫机点击在链接在查寻结果将指挥用户到不正确和引入歧途的网站而不是意欲的站点的地方。 坏所有,传染报警信息也许也是出现于查寻结果页。
Trojan.Win32.Obfuscated.gx (能也通认作为Trojan.Win32、Trojan.Win32.agent.akk、Trojan.Zlob、Trojan.Zlob-X.a、Trojan.Win32.LinkReplacer、Trojan.Win32.StarField、Trojan.Win32.Startpage.fq、Trojan.Agent、Trojan.Win32.Gorshok.a、Worm.Win32.Sober、Trojan.Vundo、Trojan.KillAV、Trojan.Win32.Patched、Trojan.Win32.CP4000、特洛伊人Win32/Qoologic,特洛伊人Win32.Murlo和其他未知的特洛伊人)单独实质上不是病毒,反而是一个恶意把戏由新的凶恶anti-spyware节目例如IE防御者或文件安全通过显示一精读用户特洛伊人被列出以上成他们的扫描结果在假系统安全戒备,误引和欺骗用户入下载和随后支付买凶恶antispyware节目简单地去除他们在用户’计算机种植的特洛伊人。
Trojan.Win32.Obfuscated.gx特洛伊人或malware能通过安装请求安装当演奏录影时,成人通常满意和性从P2P下载的明确录影分享站点或洪流,例如臭名昭著的爱迪生·陈性相片丑闻的一台假录影编解码器传染计算机。
有各种各样的方式安全地去除Trojan.Win32.Obfuscated.gx, Trojan.Win32、Trojan.Win32.agent.akk或者Trojan.Zlob。 多数新的抗病毒和anti-spyware节目更新与最新的署名应该能查出和删除和电脑程式内的病毒。 如果您的反病毒程序不适当地做它的工作,这手工撤除指示从您的系统安全地和容易地清洗和去除Trojan.Win32.Obfuscated.gx踪影。
- 点击 开始菜单 按钮,然后点击 控制板 选择,在然后双击 增加或去除节目 像或 卸载节目 链接。
- 位于 Trojan.Win32.Obfuscated.gx (或它的相关不同的名字)和双击对卸载特洛伊人的此。 跟随逐步在屏幕指示完成特洛伊人的卸载。 If the Trojan.Win32.Obfuscated.gx is not found as one of the uninstallation item, step to step 5.
- Restart the computer when prompted.
- System will continue uninstalling the Trojan. When uninstallation completed, exit “Add or Remove Programs” and “Control Panel” or “Programs and Features” folder.
- Close all programs, especially Internet Explorer and Windows Explorer.
- Run Registry Editor (regedit.exe), and then search and delete all of the following infected entries in registry:
7d4b39e4cab018496e2fe9bf9c3234b2
69c9be662f7f284aae171adeb136cb24
1bc5752bd72f44f004d9f061dd7f9e00
bcf3a381bbe26d9c1ec24bac8b18f567
8266c79a434aed795a5f3f7abb0aff0d
696ce23305a35bb118afc42d58845791
2982068d063848ddb0b8029750411a84
fe6e6a62a572e84e9eaee12eb3ee8a2b
1057a2dcd13130963be0a51c41dc4d1c
396955766b2e512bc3545a24bc485dbe
5f9523529ce2cac480acbda2b8bf4e1e
7df5417b22988d88e8080a44392ade95
cbdc7b3033e82c2065a1b48061b2ca01
6d3c4dbecf4aaf1ae826a0a7edde5951
e05997f932f826f0271cf32d00bbd3be
c18c3b4771120703624baaf835feecd8
9ceecf911241c9890541167edf53739f
40613dee6ad5fec910606c25b25262fd
3ba096caa45ab117721e725079cc53a1
bb5be1c92c299a1c6bcfe67655b0a0c7
9a9f57899a28547b04fc2da3700c95cf
7a329404de21925daacbbbee093ff6dc - Open Task Manager (taskmgr.exe) and terminate any Trojan.Win32.Obfuscated.gx (or its variant) process.
- Find and locate the path to the following Trojan infected files. Unregister these DLLs with command below at command prompt, and then rename the infected DLL files as BADFILE1.DLL, BADFILE2.DLL, BADFILE3.DLL and so on:
Command to unregister DLL (Run the command in the folder which contain the DLL by using “cd” to change directory):
regsvr32 /u FILENAME.dll (FILENAME is the name of the file that you want to unregister listed below)Trojan infect DLLs:
mlljh.dll
ibpmxtbv.dll
ljjhedc.dll
cabvie.dll
windivx.dll
ddayv.dll
vkcxxfvi.dll
ssqpo.dll
stream32a.dll
vipextqtr.dll
ecxwp.dll
gebca.dll
ddcdedd.dll
advpac.dll
tdlRMS.dll
lcxmehhg.dll
hdbxuqje.dll
mljge.dll
ddcbyvt.dll
advrepkon.dll
ddccd.dll
sgqddvym.dll
pofwjina.dll
bkfgnqhm.dll
orkbobob.dll
tuvttrr.dll
cpwvehup.dll
enhtb.dllNote: If you unable to delete or rename the files, try to restart computer in and boot in safe mode to try again.
- Go to C:\Program Files\ folder and delete the “IE Defender” folder, if found.
Note: If you unable to rename the files, try to restart computer in and boot in safe mode to try again.
- Restart computer.
- If no problem exists, delete all “BADFILE*.DLL” which renamed from infected DLLs.
- If IE homepage has been changed or hijacked, go to Start -> Control Panel -> Internet Options, click on the General tab, and then click Use Default under Home Page. Type in the new desired default homepage, then click Apply or OK button. Open a new web browser to check that IE displays the desired default homepage.
- To remove Trojan.Win32.Obfuscated.gx or its variant icons from the Desktop, simply delete them or drag and drop thems to the Recycle Bin.
Trojan.Win32.Obfuscated.gx is now completely removed and cleaned from the system. If you prefer a more automated way to delete the virus, use SmithfraudFix or follow guide below to use FixIEDef that specifically removes AntiSpyPro, Files Secure, and IEDefender and thus eliminates the “Fake Alerts” generated by Trojan-Downloader.Win32.Delf. FixIEDef also removes Trojan-Downloader.Win32.Delf from the system.
- Download FixIEDef.exe by ShadowPuterDude to the Desktop.
Note that FixIEDef.exe must be saved to desktop or it may not work properly.
- Double-click FixIEDef on desktop.

- Click OK.
- Click Scan! to start scanning the system for trace of Trojan.Win32.Obfuscated.gx and related Trojans.

- Click OK.

- Wait for the scanning process to finish. Both file system and registry will be scanned.


Note that FixIEDef will kill all copies of Internet Explorer and Explorer that are running, during removal of malicious files. The icons and Start Menu on your Desktop will not be visible while FixIEDef is removing malicious files. This is necessary to remove parts of the infection that would otherwise not be removed.
- Click Exit once FixIEDef displays the “All Finished” message.

- All FixIEDef log will be posted on the desktop. Review the content of the log if needed.
If you’re using HijackThis, there is also a how-to guide to get rid of “IE Defender” or “Files Secure” with HijackThis at Lavasoft Support forum.
IMPORTANT: This is a machine translated page which is provided "as is" without warranty. Machine translation may be difficult to understand. Please refer to original English article whenever possible.
Share and contribute or get technical support and help at My Digital Life Forums.
Related Articles
- Don’t Get Infected by Trojan.Zlob When Browsing Edison Chen Sex Scandal Photo
- Beware of Spyware While Browsing Edison Chen’s Sex Scandal Photos
- Remove or Hide Windows Live Messenger Tabs
- Recover and Reclaim ‘Lost’ Disk Space After Installing Windows Vista Service Pack 1 (SP1)
- How to Recover a Soaked Cell Phone
- Windows Defender Review by Spyware Confidential
- Download RED (Remove Empty Directories) for Windows PC
- Remove Ads from Windows Live Messenger with A-Patch and Customize Messenger Options and Visualisation
- Unable to Clean Install Windows Vista with Upgrade Edition Product Key
- Delete a File Permanently




























February 16th, 2008 22:23
[...] you choose to remove this spyware manually, you can refer the removal procedure here. Get help or contribute tips or tricks at My Digital Life [...]
February 23rd, 2008 17:02
[...] there is another virus, Trojan.Zlob, which is actually variant of each other (see Trojan.Zlobremoval and Trojan.Win32.Obfuscated.gx instructions), widely spread over some websites that published these hot pornographic photos. Trojan.Zlob is a [...]
February 27th, 2008 13:20
Good I like the article very much.Keep up.
I wish I could more about article regarding server hacking & its prevention.
March 10th, 2008 17:01
thank you very much for your wonderful guide to remove the virus
March 22nd, 2008 18:58
thanke soo much man you helped me alottt…keep it up man wee need man like you an less of this people who tries to destroy our life
August 13th, 2008 10:23
Thanks a million saved my laptop! i had a stupid trojan that wouldnt let me even brows the net it would tell me to download some stupid antivirus thing and this saved my life thanks so much for being loyal and not like other people who tell you to download and it makes it even worst. Thanks