Monday, 13 January 2014

How to Completely Remove Trojan:JS/Febipos.E From Your Computer?

Your computer infected by Trojan:JS/Febipos.E? Don’t know how to get rid of it from your PC? Frankly, if your computer gets infected by this threat, it will be at risk. You should get rid of it as soon as possible before it causes more troubles. Follow the guide below and learn to remove the Trojan completely.
More information about Trojan:JS/Febipos.E:
Trojan:JS/Febipos.E is a newly released destructive Trojan horse which can damage the targeted computers severely. Once it gets into your PC, remote hackers can easily gain access to and control your computer system and steal your sensitive information. One trait of this Trojan is that it can hijack your facebook to like unwanted page or post, post something or comment on some contents without your permission. It can also send messages which contain itself and other malware to your facebook friends. In this way, it can spread more PCs and steal more people’s data. This Trojan may install itself in your system while you are using Internet explorer or chrome to visit any unknown site or download freeware programs from Internet unwarily. It can also spread via spam email attachments or unknown links.
Usually, you won’t realize this Trojan is installed until you do a scan of the computer. If your PC is infected by this Trojan, your browsing activities will be interrupted and the web browser is also hijacked. A lot of unwanted, irrelevant and potentially hostile websites will open automatically when you use the infected web browser. Moreover, it can open a backdoor on your computer so that attackers can access the computer without your knowledge. Your important personal information may be stolen.
Since Trojan:JS/Febipos.E is so dangerous, , for the sake of your security and computer data, you need to get rid of it promptly. If antivirus program on your PC cannot fix the problem, follow the steps below to remove Trojan:JS/Febipos.E completely.
Trojan:JS/Febipos.E removal guide:
Step 1. Boot your computer in Safe Mode.
Start your computer and keep pressing F8 constantly before Windows loads. Choose Safe Mode and then press Enter.

Step 2. Delete the malicious files of the Trojan.
Click Start button, click Folder Options in Control Panel. Under View tab, select Show hidden files and folders and uncheck Hide protected operating system files (Recommended), and then click OK.

Then search for and delete the files below.
%UserProfile%\Application Data\Microsoft\[random].exe
%System Root%\Samples
%User Profile%\Local Settings\Temp
%Documents and Settings%\All Users\Start Menu\Programs\Trojan:JS/Febipos.E
%Documents and Settings%\All Users\Application Data\Trojan:JS/Febipos.E
doguzeri.dll
3948550101.exe
3948550101.cfg
%Program Files%\Trojan:JS/Febipos.E
%Program Files%\Trojan:JS/Febipos.E
C:\ProgramData\[random numbers]\
Step 3. Delete the registry entries created by the Trojan.
 To open Windows Registry Editor, click Start, go to Run, type regedit in the box and click OK.

Search for the following registry entries and delete them.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmpeng.exe “Debugger” = ‘svchost.exe’
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe “Debugger” = ‘svchost.exe’
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Trojan:JS/Febipos.E
HKEY_LOCAL_MACHINE\SOFTWARE\Trojan:JS/Febipos.E
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings WarnOnHTTPSToHTTPRedirect = 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings WarnOnHTTPSToHTTPRedirect = 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore DisableSR = 1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ekrn.exe “Debugger” = ‘svchost.exe’
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msascui.exe “Debugger” = ‘svchost.exe’
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run 3948550101
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “xas”
HKEY_CURRENT_USER\Software\Trojan:JS/Febipos.E

Suggestion:
If you are not a computer expert, it is not suggested that you delete Trojan:JS/Febipos.Emanually because the manual steps above require you to have enough computer skills.  You may end up damaging your computer severely of you delete wrong files or registry key which contains information and settings for all the hardware, operating system software etc during the manual removal. To avoid this situation, download and install a professional removal tool like Mighty Uninstaller to delete the files and registry entries of the trojan automatically. After all the leftover files and registry entries of the threat are deleted, you can successfully get rid of the Trojan.

No comments:

Post a Comment