Title: Win32/Dofoil
Also known as: Dofoil
Remove Win32/Dofoil
Removal instructions
Severity scale: (35 / 100)
Win32/Dofoil is Trojan downloader that is set to follow control commands received from its remote server. In most of the cases, Dofoil is used for downloading spam capable software or rogue security software, such as the latest family of fake defragmenters including System Fix and others. So, it becomes obvious that this Trojan is created for commercial objectives and, if not eliminated, will lead its victims at privacy risk.
Win32/Dofoil trojan infiltrates target computers through spam campaigns based on fake letters and malicious attachments. In most of the cases, victims report about such files found attached in their emails:
- New_Password_IN46537.zip
- Invoice_Copy.zip
- Facebook_Password.zip
Typically, letter announces something like that:
iTunes
From: account.sn.5890@itunes.apple.com Subject: Your iTunes Gift Certificate
Hello,
You have received an Itunes Gift Certificate in the amount of $50 You can find your certificate code in attachment below.
Then you need to open iTunes. Once you verify your account, $50 will be credited to your account. So you can start buying video, music, games right away.
iTunes Store.
More than 13000 computers have been already found to have Win32/Dofoil Trojan this month. If you have also received such or similar suspiciously looking email from iTunes, Facebook or other company, make sure you run a full system scan and remove Win32/Dofoil Trojan.
Automatic Win32/Dofoil removal:
We might be affiliated with any product we recommend on the site. Full disclosure in our Agreement of Use.
By Downloading any provided Anti-spyware software to remove Win32/Dofoil you agree to our privacy policy and agreement of use.
Malwarebytes Anti Malware
We are testing Malwarebytes Anti Malware's efficiency at removing Win32/Dofoil
(2011-11-25 12:20:58)
We are testing Spyware Doctor's efficiency at removing Win32/Dofoil
(2011-11-25 12:20:58)
We are testing STOPzilla's efficiency at removing Win32/Dofoil
(2011-11-25 12:20:58)
Win32/Dofoil manual removal:
Kill processes: \dxdiag.exe \lxdiag.exe \ctfmon.exe \gefreg.exe %appdata%\csrss.exe %appdata%\smss.exe
Delete registry values:HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run %appdata%\csrss.exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run %appdata%\smss.exe"
Delete files:\dxdiag.exe \lxdiag.exe \ctfmon.exe \gefreg.exe %appdata%\csrss.exe %appdata%\smss.exe
Phone Support to remove Win32/Dofoil
QR code for Win32/Dofoil removal instructions:
QR is short for Quick Response. They can be read quickly by the mobile phones. QR codes can store more data than standard barcodes, including url links, geo coordinates, and text.
The reason we add QR code to the website is that parasites like Win32/Dofoil are really hard to remove on infected computer.
you can quicly scan the QR code with your mobile device and have manual removal instructions to uninstall Win32/Dofoil right in your pocket.
Simply use the QR scanner and read removal instructions from mobile device.
SYMPTOMS OF trojans INFECTION
Win32/Dofoil is a trojan parasite. Like other trojans, it infiltrates into your system disguised as a codecs, an update to some common software like Adobe Flash or Java, a mail attachment or a useful program and makes your PC vulnerable to other parasites.
Win32/Dofoil might download other parasites, steal your information, perform redirections and provide full access to your PC for criminals. Your PC would be used for illegal activities like laundering money or providing platform for DDOS attacks.
It is mostly impossible to determine if system contains trojans like Win32/Dofoil. these parasites are designed to work silently, and provide infiltration platform for other infections, like spyware, adware or fake antiviruses. It is imposible to determine what parasites accompany Win32/Dofoil thus we recommend scanning your PC with anti-malware software.
Information added: 2011-11-23 15:05:34
Information updated: 2011-11-23 15:05:34
Additional resources:
Attention: If you know know a reputable website reated to security threats, please add a link here: add
url
more resources
|
Post Comment: