Click on screenshot to zoom
Danger level 8
Type: Trojans
Common infection symptoms:
  • Connects to the internet without permission
  • Installs itself without permissions
  • Slow Computer
  • Slow internet connection

Trojan.Vbot.G

Trojan.Vbot.G is a multi-layered computer threat that can be detrimental to you in many ways. The most annoying thing about this parasite is that it does not come alone. There are a lot of files Trojan.Vbot.G is associated with that are very dangerous on their own already, but when they come in a batch together with this Trojan, you can be sure that is spells nothing but trouble. Therefore, you need to periodically scan your computer for any infection, because such parasites like Trojan.Vbot.G do not have an interface and it might take some time for you to realize that something is wrong.

This Trojan can spread via Windows Live Messenger files transfers and network and removable drives. It shows that you should enable a security scan of all the external objects that arrive into your system. When Trojan.Vbot.G enters your system, it overrides the display, and as a results the files which have the 'hidden' attribute are no longer displayed. It makes it seem like some of your important files have disappeared, but they all are still there, just hidden from your view by the parasite.

This Trojan is dangerous, because it does not remain still in your computer. It can communicate with other computers over the network, and it will inform the hacker who has created it about the new infection. Afterwards Trojan.Vbot.G will receive new data configuration information and download and execute other arbitrary files. This is especially important, because a few files associated with this Trojan are classified as malware droppers. It means that Trojan.Vbot.G can be responsible for even more infections plaguing your computer.

If that weren't enough Trojan.Vbot.G can also steal your data by the means of keylogging and send it out to cyber criminals. The data which can be recorded and then leaked includes your usernames, computer names, user account names, passwords, credit card numbers and what not. Trojan.Vbot.G loads automatically every time you turn on your computer because during the installation it performs changes in the system allowing it to do so.

You need to remove Trojan.Vbot.G from your system immediately or else your sensitive information will be stolen and used for illegal purposes. Since this Trojan uses rootkits to hide itself from you and various security programs, it is very hard to remove it manually. You are advised to acquire a computer safeguard program which can crack down rootkits and then delete Trojan.Vbot.G automatically for you. Do no forget that the longer you allow this parasite to stay in your computer the more malware it can download, so terminate the pest as soon as you can.

Download Spyware Removal Tool to Remove* Trojan.Vbot.G
  • Quick & tested solution for Trojan.Vbot.G removal.
  • 100% Free Scan for Windows
disclaimer

How to manually remove Trojan.Vbot.G

Files associated with Trojan.Vbot.G infection:

svcchost.exe
2465de9bcdd94be.exe
rundll32.exe
Student.exe
RAVCpl32.exe
mqq5aq.exe
o8l6go.exe
jmhqu.exe
jizz.exe
hmhfr.exe
aj20.exe
2ubrc.exe
2qb9w.exe
0ymn.exe
i1eaavmm.exe
ScanDisc.exe
aadrive32.exe
TimeSync.exe
ipsec.sys
nsn13B.exe
netbt.sys
fa78.dll
dfsc.sys
.exe
WinDefender.exe
mac.exe
Wiscr.exe
puma.sys
MSN_WebCamSpy.exe
administration.exe
msmsgs.exe
vio.exe
system.exe
lsq.exe
jikd.exe
biv.exe
svflooje.exe
Saberz.r01.exe
javaupdater.exe
Clownfish.exe
oulwsvm.exe
regsvc32.exe
WLAcol.dll
iapadWMA.dll
0.18647449043215647.exe
0filsys.bin.exe
smsTx.exe
picture.scr
securitymanager.exe
Aszgzg.exe
7eb2eee8.dll
XoftSpySE.exe
WinRAR.exe
svc2dll.exe
mog.exe
KillProcessSetup.exe
kbmovm.dll
IlvMoney1105.sys
bfpc9.dll
bbprint.exe
8F-bTxv.dll
Flash_Player.exe
Vknt.exe
scanquery.dll
kbdjpn32.exe
clipsrv.exe
svsht2.exe
svsht.exe
y69066.exe
xc3hh4.exe
fz77q.exe
acxw.exe
736si.exe
4jbpm.exe
3wf5d.exe
22wwk.exe
1jaxe3.exe
0kfp.exe
gtp3.exe
Cain.exe
avdv.exe
sysp.cpl
resultbar143.exe
GoogleUpdateBeta.exe
AntiVirus AntiSpyware.exe
svngage.exe
resultbrowser119.exe
questresult121.exe
dn.exe
zat5.exe
csrss.exe.exe
TXP.exe
riitd.exe
m.2AE68.tmp.exe
msmon.exe
msado320.tlb
IVV.exe
wins.exe
USBGuard.exe
rufbvrsc.exe
rpchttp32.exe
PCFix.exe
Modulo.exe
m.218.tmp.exe
chicken_invaders_4_plus8.exe
chicken_invaders_4_plus5_trainer.exe
advserv.exe
binternet.exe
Uneraser_Setup.exe
UsbCheck.exe
Spoolvmx.exe
qPGLAEI.dll
LaunchChainz.exe
iconcs177016015.exe
d697a702.dll
bitutil.exe
access[2].exe
-e-2rrGtm__9I.dll
dtshldlp.exe
MWSBAR.DLL
qtfcyyp.exe
svcnost.exe
MediaCoder-0.7.2.4582.exe
ComboFix.exe
umdmgr.exe
sborka_blackmanos_13_69.exe
LEX.exe
gfWFwzSCBSga.exe
8bq9.exe
StartUp.exe
mscfg32.exe
LGxJuggkBGegHQ.exe
drm.exe
VRT1.tmp
sysr.cpl
sngrrm.exe
d3dlib.exe
aecces.exe
pleneWl.dll
patchcore716pe0.exe
crqytiqlajb.exe
AntiVirus_System_2011.exe
zlxfmompe.exe
NlsData000d32.exe
aHvFmtjxlhgIe.exe
audio.exe
andy133.exe
javachelper.dll
msnmsgra.exe
winb.exe
adtech2005.exe
prun.exe
lpcywinp.exe
ntsmod.exe
Localhost.exe
Mga Dokumento.exe
prunnet.exe
DisTM.exe
snsrvc32.exe
nvscv32.exe
dewin32.exe
USB GATE.exe
ctfmon.exe
OPR.exe
winlogon.exe
CalcImpSAT[1].exe
wndrive32.exe
inandrom.dll
cmd.exe
alg.exe
wilogon.exe
winxp.exe
hostplug.exe
lssas.exe
svchost.exe
syre32.exe
geurge.exe
bill103.exe
msnmsgr.exe
TT.exe
MPTols.exe
nsvsc32.exe
winayuda.exe
net.net
Scvhosts.exe
Server.exe
XP.exe
csrss.exe
Test_123.exe
winlogon32.exe
geindigo.dll
sesingul.dll
brconcho.dll
apkruisi.dll
lspolysp.dll
4020.EXE
services.exe
lsass.exe
winfiles.exe
explorer.exe
dldesmos.dll
Explorer.pif
temp2.exe
rpc.exe
msiupdate.exe
A__MYDOCU~1[1].exe
Windows Explorer.exe
My Documents.exe
Copy of My Documents.exe
Athan.exe
swcupdate.exe
svpodsom.dll
netsvcs32.exe
kbdlwa.dll
elsef10.dll
dwid32.dll
dXXBTPbLqyCp.exe
clsidmount.exe
ydw.exe
Recycle.Bin.exe
R66v.exe
msible.dll
lbe.exe
KBDMFisv.dll
dxdiag.exe
6DDF6564D6B.exe
shabi.exe

Trojan.Vbot.G DLL's to remove:

MWSBAR.DLL
fa78.dll
WLAcol.dll
iapadWMA.dll
7eb2eee8.dll
kbmovm.dll
bfpc9.dll
8F-bTxv.dll
scanquery.dll
qPGLAEI.dll
d697a702.dll
-e-2rrGtm__9I.dll
pleneWl.dll
javachelper.dll
inandrom.dll
geindigo.dll
sesingul.dll
brconcho.dll
apkruisi.dll
lspolysp.dll
dldesmos.dll
svpodsom.dll
kbdlwa.dll
elsef10.dll
dwid32.dll
msible.dll
KBDMFisv.dll

Trojan.Vbot.G processes to kill:

svcchost.exe
2465de9bcdd94be.exe
rundll32.exe
Student.exe
RAVCpl32.exe
mqq5aq.exe
o8l6go.exe
jmhqu.exe
jizz.exe
hmhfr.exe
aj20.exe
2ubrc.exe
2qb9w.exe
0ymn.exe
4020.EXE
i1eaavmm.exe
ScanDisc.exe
aadrive32.exe
TimeSync.exe
nsn13B.exe
.exe
WinDefender.exe
mac.exe
Wiscr.exe
MSN_WebCamSpy.exe
administration.exe
msmsgs.exe
vio.exe
system.exe
lsq.exe
jikd.exe
biv.exe
svflooje.exe
Saberz.r01.exe
javaupdater.exe
Clownfish.exe
oulwsvm.exe
regsvc32.exe
0.18647449043215647.exe
0filsys.bin.exe
smsTx.exe
securitymanager.exe
Aszgzg.exe
XoftSpySE.exe
WinRAR.exe
svc2dll.exe
mog.exe
KillProcessSetup.exe
bbprint.exe
Flash_Player.exe
Vknt.exe
kbdjpn32.exe
clipsrv.exe
svsht2.exe
svsht.exe
y69066.exe
xc3hh4.exe
fz77q.exe
acxw.exe
736si.exe
4jbpm.exe
3wf5d.exe
22wwk.exe
1jaxe3.exe
0kfp.exe
gtp3.exe
Cain.exe
avdv.exe
resultbar143.exe
GoogleUpdateBeta.exe
AntiVirus AntiSpyware.exe
svngage.exe
resultbrowser119.exe
questresult121.exe
dn.exe
zat5.exe
csrss.exe.exe
TXP.exe
riitd.exe
m.2AE68.tmp.exe
msmon.exe
IVV.exe
wins.exe
USBGuard.exe
rufbvrsc.exe
rpchttp32.exe
PCFix.exe
Modulo.exe
m.218.tmp.exe
chicken_invaders_4_plus8.exe
chicken_invaders_4_plus5_trainer.exe
advserv.exe
binternet.exe
Uneraser_Setup.exe
UsbCheck.exe
Spoolvmx.exe
LaunchChainz.exe
iconcs177016015.exe
bitutil.exe
access[2].exe
dtshldlp.exe
qtfcyyp.exe
svcnost.exe
MediaCoder-0.7.2.4582.exe
ComboFix.exe
umdmgr.exe
sborka_blackmanos_13_69.exe
LEX.exe
gfWFwzSCBSga.exe
8bq9.exe
StartUp.exe
mscfg32.exe
LGxJuggkBGegHQ.exe
drm.exe
sngrrm.exe
d3dlib.exe
aecces.exe
patchcore716pe0.exe
crqytiqlajb.exe
AntiVirus_System_2011.exe
zlxfmompe.exe
NlsData000d32.exe
aHvFmtjxlhgIe.exe
audio.exe
andy133.exe
msnmsgra.exe
winb.exe
adtech2005.exe
prun.exe
lpcywinp.exe
ntsmod.exe
Localhost.exe
Mga Dokumento.exe
prunnet.exe
DisTM.exe
snsrvc32.exe
nvscv32.exe
dewin32.exe
USB GATE.exe
ctfmon.exe
OPR.exe
winlogon.exe
CalcImpSAT[1].exe
wndrive32.exe
cmd.exe
alg.exe
wilogon.exe
winxp.exe
hostplug.exe
lssas.exe
svchost.exe
syre32.exe
geurge.exe
bill103.exe
msnmsgr.exe
TT.exe
MPTols.exe
nsvsc32.exe
winayuda.exe
Scvhosts.exe
Server.exe
XP.exe
csrss.exe
Test_123.exe
winlogon32.exe
services.exe
lsass.exe
winfiles.exe
explorer.exe
temp2.exe
rpc.exe
msiupdate.exe
A__MYDOCU~1[1].exe
Windows Explorer.exe
My Documents.exe
Copy of My Documents.exe
Athan.exe
swcupdate.exe
netsvcs32.exe
dXXBTPbLqyCp.exe
clsidmount.exe
ydw.exe
Recycle.Bin.exe
R66v.exe
lbe.exe
dxdiag.exe
6DDF6564D6B.exe
shabi.exe

Remove Trojan.Vbot.G registry entries:

HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Local security authentication server
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Yahoo Messengger
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN winserver
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWSNT\CURRENTVERSION\WINLOGON\USERINIT\ userinit
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{46C82107-C059-4B5A-8BEE-361B06DB044C}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{6742CC3A-65E8-4ED9-B051-AA119195C7BE}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{7B618C0C-8D13-4F49-8559-BE04DC96899C}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{96F7F230-8ADE-4930-A88F-3547C6A30BFF}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{98A60C8C-2568-4029-9FB2-F2ED7E2DA8E8}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{C94138D5-BED4-4865-9DD5-4F9955277EB0}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{E30D4ED9-0D46-4757-ADE5-1736BEFCC15A}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ %s
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ AntiMW
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Athan
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ ayuda
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ DisTM
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Dmbksf
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ ewrgetuj
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ GoogleUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Host Process for Windows Services
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ hostplug
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Internet Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ media
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Microsoft
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Microsoft Driver Setup
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Microsoft Error Reporting
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ MicrosoftNAPC
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ MSN
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ MSWUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ net
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ prunnet
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ regdiit
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ s%s
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Scheluder
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ syre32
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ sysfbtray
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ System File
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Test_123
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ USB GATE
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ windebug
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Windows DLL Driver
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Windows Firewall
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Windows Live Conctacts Get
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Windows Log Agent
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Windows Logon Applicationedc
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Windows RPC Service
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ WinNT 32
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ WinsysMon
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ ÿÿÿnvscv32.exe
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\adtech2005
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ntsmod
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\OPR
RUNNING PROGRAM\ctfmon.exe
RUNNING PROGRAM\explorer.exe
RUNNING PROGRAM\Server.exe
Disclaimer

Post comment — WE NEED YOUR OPINION!

Comment:
Name:
Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.