Archive for September, 2009

NetFilter.exe is trojan Agent

Monday, September 28th, 2009

NetFilter.exe is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: NetFilter
Filename: NetFilter.exe
Registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | MSDRV

Command: C:\WINDOWS\system32\NetFilter.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKLM\..\Run: [MSDRV] NetFilter.exe

Combofix/RSIT Line:

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“MSDRV”=C:\WINDOWS\system32\NetFilter.exe [2009-09-23 122880]

Description: trojan that installed by Alpha Antivirus rogue antispyware program

How to remove: use these Alpha Antivirus removal instructions

How to remove AlphaAV.exe, What is AlphaAV.exe

Monday, September 28th, 2009

AlphaAV.exe is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: AlphaAV
Filename: AlphaAV.exe
Registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | AlphaAV

Command: C:\Program Files\AlphaAV\AlphaAV.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKLM\..\Run: [AlphaAV] C:\Program Files\AlphaAV\AlphaAV.exe

Combofix/RSIT Line:

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“AlphaAV”=C:\Program Files\AlphaAV\AlphaAV.exe [2009-09-26 1581056]

Description: main file of Alpha Antivirus rogue antispyware program

How to remove: use these Alpha Antivirus removal instructions

How to remove SecuritySoldier.exe, What is SecuritySoldier.exe

Saturday, September 26th, 2009

This is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: SecuritySoldier
Filename: SecuritySoldier.exe
Registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | SecuritySoldier

Command: C:\Program Files\SecuritySoldier Software\SecuritySoldier\SecuritySoldier.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKCU\..\Run: [SecuritySoldier] C:\Program Files\SecuritySoldier Software\SecuritySoldier\SecuritySoldier.exe -min

Description: main component of SecuritySoldier rogue antispyware program

How to remove: use these SecuritySoldier removal instructions

How to remove SecurityFighter.exe, What is SecurityFighter.exe

Thursday, September 24th, 2009

SecurityFighter.exe is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: SecurityFighter
Filename: SecurityFighter.exe
Registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | SecurityFighter

Command: C:\Program Files\SecurityFighter Software\SecurityFighter\SecurityFighter.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKCU\..\Run: [SecurityFighter] C:\Program Files\SecurityFighter Software\SecurityFighter\SecurityFighter.exe -min

Description: main file of SecurityFighter fake antispyware program

How to remove: use these SecurityFighter removal instructions

wsn.bat is component of Green AV

Tuesday, September 22nd, 2009

This is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: wsn
Filename: wsn.bat
Registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | RANDOM NUMBERS

Command: C:\ProgramData\gra\wsn.bat
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKCU\..\Run: [RANDOM NUMBERS] C:\ProgramData\gwr\wsn.bat
O4 – HKCU\..\Run: [RANDOM NUMBERS] C:\ProgramData\gra\wsn.bat

Description: component of Green AV rogue antivirus/antispyware program

How to remove: use these Green AV removal instructions

wsga05.exe is component of Green AV

Tuesday, September 22nd, 2009

wsga05.exe is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: wsga05
Filename: wsga05.exe
Command: C:\ProgramData\gra\wsga05.exe
Description: trojan Agent installed by Green AV fake antivirus program

How to remove: use these Green AV removal instructions

What is SaveArmor.exe, How to remove SaveArmor.exe

Monday, September 21st, 2009

This is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: SaveArmor
Filename: SaveArmor.exe
Registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | SaveArmor

Command: C:\Program Files\SaveArmor Software\SaveArmor\SaveArmor.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKCU\..\Run: [SaveArmor] C:\Program Files\SaveArmor Software\SaveArmor\SaveArmor.exe -min

Description: main component of SaveArmor rogue antispyware program

How to remove: use these SaveArmor removal instructions

What is SaveDefender.exe, How to remove SaveDefender.exe

Monday, September 21st, 2009

This is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: SaveDefender
Filename: SaveDefender.exe
Registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | SaveDefender

Command: C:\Program Files\SaveDefender Software\SaveDefender\SaveDefender.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKCU\..\Run: [SaveDefender] C:\Program Files\SaveDefender Software\SaveDefender\SaveDefender.exe -min

Description: main file of SaveDefender rogue antispyware program

How to remove: use these SaveDefender removal instructions

revulazo.dll is trojan Vundo

Sunday, September 20th, 2009

This is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: revulazo
Filename: revulazo.dll
Command: c:\windows\system32\revulazo.dll
Description: component of a trojan Vundo

How to remove: use Malwarebytes` Anti-malware + use SUPERAntiSpyware

wogipute.dll is trojan Vundo

Sunday, September 20th, 2009

This is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: wogipute
Filename: wogipute.dll
Registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6933d543-b109-40aa-9185-58ccc8241c09}

Command: c:\windows\system32\wogipute.dll
CLSID: {6933d543-b109-40aa-9185-58ccc8241c09}
Startup Type: BHO
HijackThis Category: O2
HijackThis Line:

O2 – BHO: (no name) – {6933d543-b109-40aa-9185-58ccc8241c09} – c:\windows\system32\wogipute.dll

Combofix/RSIT Line:

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6933d543-b109-40aa-9185-58ccc8241c09}]
2009-06-20 03:46 50688 –sha-w- c:\windows\system32\wogipute.dll

Description: trojan Vundo that installs rogue antispyware programs

How to remove: use Malwarebytes` Anti-malware