Start to remove Trojan:Win32/Choke now!
Trojan:Win32/Choke description and removal instruction

Trojan:Win32/Choke

Free Trojan:Win32/Choke Scan

Technical information
Payload
Removal instructions

Technical information

The Trojan:Win32/Choke will install rogue security software HDDPhysic into the affected machines without users knowledge. The Trojan:Win32/Choke file size is 184320 bytes.

Payload

Once launched, the Trojan:Win32/Choke performs the following actions:

  • Download rogue security tool HDDPhysic from the following domains:
    http://www.rlbyte.com/
  • Modify the properties of the following files:
    %SYSTEMROOT%:\WINDOWS\winsxs\msil_microsoft.iis.powershell.provider_31bf3856ad364e35_6.1.7600.16385_none_13ad2b6b48f855e2\\Microsoft.IIS.PowerShell.Provider.dll

    (184320 bytes; detected by HitMalware as " Trojan:Win32/Choke")
  • Removal instructions

    If your machine doesn't have antivirus/antispyware, please take the following steps to resolve the problems caused by Trojan:Win32/Choke:

    1. Replace the infected file Microsoft.IIS.PowerShell.Provider.dll for free by using Microsoft.IIS.PowerShell.Provider.dll repair tool - DLL Suite. See how to replace Microsoft.IIS.PowerShell.Provider.dll by using DLL Suite.

    2. Perform a full Trojan:Win32/Choke scan by using the latest antivirus/antispyware HitMalware.
    (Download Trial Version Now)

    MD5: 81642818164281


    How to replace Microsoft.IIS.PowerShell.Provider.dll by using DLL Suite

  • Download DLL Suite, install and run
  • Click "Start Scan" button to check Microsoft.IIS.PowerShell.Provider.dll file
  • Choose Microsoft.IIS.PowerShell.Provider.dll and click "More Information"
  • Download Microsoft.IIS.PowerShell.Provider.dll for free from the open web page
  • Save Microsoft.IIS.PowerShell.Provider.dll to its default folder to replace infected Microsoft.IIS.PowerShell.Provider.dll file.
  • Download Trojan:Win32/Choke Removal Tool Now

    Download Trojan:Win32/Choke Removal Tool Now