Archive for the 'HijackThis' Category

eneticab.dll is a component of trojan Vundo

Sunday, February 15th, 2009

This is an harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: eneticab
Filename: eneticab.dll
Command: %windir%\eneticab.dll
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKLM\..\Run: [Hqefudivosogike] rundll32.exe “C:\WINDOWS\eneticab.dll”,e

Description: component of trojan Vundo

How to remove: How to remove Trojan Vundo

Uguguyirog.dll is a component of trojan Vundo

Sunday, February 15th, 2009

This is an harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: Uguguyirog
Filename: Uguguyirog.dll
Command: %windir%\Uguguyirog.dll”
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKLM\..\Run: [Bvaduyokuyepe] rundll32.exe “C:\WINDOWS\Uguguyirog.dll”,e

Description: component of trojan Vundo

How to remove: How to remove Trojan Vundo

prunnet.exe is a trojan downloader

Sunday, February 15th, 2009

This is an harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: prunnet
Filename: prunnet.exe
Command: %windir%\system32\prunnet.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKLM\..\Run: [prunnet] “C:\WINDOWS\system32\prunnet.exe”

Description: trojan downloader

How to remove: Use Malwarebytes Antimalware

wcs.exe a variant of the Adware/Netproject malware

Saturday, February 14th, 2009

This is an harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: wcs
Filename: wcs.exe
Command: %programfiles%\Applications\wcs.exe
Startup Type: HKLM->Policies\Explorer\Run:
HijackThis Category: O4
HijackThis Line:

O4 – HKLM\..\Policies\Explorer\Run: [smile] C:\Program Files\Applications\wcs.exe

Description: variant of the Adware/Netproject malware

How to remove: Use HijackThis.

algg.exe is a trojan downloader

Saturday, February 14th, 2009

This is an harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: algg
Filename: algg.exe
Registry key: key
Command: %windir%\system32\algg.exe
Startup Type: HKCU->run
HijackThis Category: O4
HijackThis Line:

O4 – HKCU\..\Run: [wblogon] C:\WINDOWS\system32\algg.exe

Description: trojan downloader

How to remove: Use HijackThis.

VirusRL2009.exe is Virus Response Lab 2009 rogue antispyware

Saturday, February 14th, 2009

This is an harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: VirusRL2009
Filename: VirusRL2009.exe
Command: %programfiles%\VirusRL2009\VirusRL2009.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKCU\..\Run: [VirusRL2009] “C:\Program Files\VirusRL2009\VirusRL2009.exe”

Description: Virus Response Lab 2009 rogue antivirus component

How to remove: How to remove VirusResponseLab

lockx.exe is a W32/Sdbot-ADD worm

Saturday, February 14th, 2009

This is an harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: lockx
Filename: lockx.exe
Command: %windir%\system32\lockx.exe
Startup Type: HKLM->RunServices, HKCU->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKLM\..\RunServices: [strtas] lockx.exe
O4 – HKCU\..\Run: [strtas] lockx.exe

Description: W32/Sdbot-ADD worm

How to remove: Use HijackThis

bfgtoolbar.dll is adware

Saturday, February 14th, 2009

This is an harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: bfgtoolbar
Filename: bfgtoolbar.dll
Command: [%PROGRAM_FILES%]\bfgtoolbar\bfgtoolbar.dll
CLSID: {4E7BD74F-2B8D-469E-86BD-FD60BB9AAE3A}
Startup Type: BHO
HijackThis Category: O2
HijackThis Line:

O2 – BHO: (no name) – {4E7BD74F-2B8D-469E-86BD-FD60BB9AAE3A} – (no file)

Description: Adware OneToolBar
Notes: Big Fish Games Toolbar

How to remove: Use HijackThis.

djvlg2072387.exe is a trojan fakealert component

Sunday, February 8th, 2009

This is an harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: djvlg2072387
Filename: djvlg2072387.exe
Command: %appdata%\Google\djvlg2072387.exe
Startup Type: HKCU->run
HijackThis Category: O4
Description: trojan fakealert component
Notes: The trojan uses fake Security Center Alert to trick you into purchasing rogue antispyware

How to remove: How to remove Spyware.ISpynow, win32.zafi.b, Win32.Netsky.Q, Trojan.Zlob.G (Fake Security Center Alert)

SafeTest.exe is a malware

Monday, February 2nd, 2009

This is an harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: SafeTest
Filename: SafeTest.exe
Registry key:

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“SafeTest”=”c:\windows\system32\SafeTest.exe” [2009-01-16 69484]

Command: c:\windows\system32\SafeTest.exe
Startup Type: HKLM->Run
HijackThis Category: O4
Description: unknown malware