Home Blog

Trojan.Smowbot Removal – How to Remove Trojan.Smowbot easily from Your PC

Posted by in Blog backdoor trojan
on October 23rd, 2012 | Leave a comment

Trojan.Smowbot is a new detected Trojan used to download more pc threats to the infected computer. When it is triggered, it attempts to use the networking and connect itself to server. Hackers will send commands to the Trojan and control it to perform malicious actions. Trojan.Smowbot can download programs such as Win 8 Defender 2013, execute programs, update itself and send spam message to spread itself. Meanwhile, it damages the system by changing key settings such as firewall. No matter when it receives commands or downloads files, you will experience slow internet and slow computer. It is important to wipe off the backdoor Trojan quickly or your computer will become a hot target of virus attacks. Computers with a back door are very vulnerable. Do you want to know how to remove Trojan.Smowbot completely? Keep reading.

How to delete Trojan.Smowbot manually
Though manual way is not the best way to get rid of the Trojan, it is still a possible way for users who have advanced pc knowledge and skills.
1. Press Ctrl+Alt+Del to run Task Manager. Click process tab and kill the following

actxprxy.exe
admparse.exe

2. Remove the copy of Trojan.Smowbot

%System%\actxprxy.exe
%System%\admparse.exe

3. Run registry editor to wipe off related registry entries

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\”smwcore” = “%System%\admparse.exe”
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\”%System%\actxprxy.exe” = “%System%\actxprxy.exe:*:Enabled:enable”
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\”%System%\admparse.exe” = “%System%\admparse.exe:*:Enabled:enable”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FWCFG\”ConsoleTracingMask” = “4294901760″
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FWCFG\”EnableConsoleTracing” = “0″
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FWCFG\”EnableFileTracing” = “0″
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FWCFG\”FileDirectory” = “%Windir%\tracing”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FWCFG\”FileTracingMask” = “4294901760″
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FWCFG\”MaxFileSize” = “1048576″
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\NAP\Netsh\”Active” = “1″
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\NAP\Netsh\”ControlFlags” = “1″
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\NAP\Netsh\”LogSessionName” = “stdout”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\NAP\Netsh\Napmontr\”BitNames” = “NAP_TRACE_BASE NAP_TRACE_NETSH”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\NAP\Netsh\Napmontr\”Guid” = “710adbf0-ce88-40b4-a50d-231ada6593f0″
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\qagent\”Active” = “1″
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\qagent\”ControlFlags” = “1″
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\qagent\”LogSessionName” = “stdout”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\qagent\traceIdentifier\”BitNames” = “Error Unusual Info Debug”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\qagent\traceIdentifier\”Guid” = “b0278a28-76f1-4e15-b1df-14b209a12613″

Best way to remove Trojan.Smowbot
Nowadays, a virus removal program is the best way to cure a computer infected by Trojans. Such software becomes very popular since it brings great convenience to users. A virus removal program can save your effort and time on searching for malicious components created by Trojan.Smowbot, and it also provide safe solution to remove them completely. Unlike manual way which may lead to system damage, a virus removal program will guarantee computer stability. To remove Trojan.Smowbot completely and safely, you should an advanced removal program like Spyware Cease.

Leave a Reply