Archive for the 'Trojan' Category

What is winlogon86.exe, How to remove winlogon86.exe

Saturday, November 28th, 2009

winlogon86.exe is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: winlogon86
Filename: winlogon86.exe
Command: C:\WINDOWS\system32\winlogon86.exe
Startup Type: System.ini
HijackThis Category: F2
HijackThis Line:

F2 – REG:system.ini: UserInit=C:\WINDOWS\system32\winlogon86.exe

Description: trojan that installed with rogue antispyware program.

How to remove: use HijackThis + Malwarebytes` Anti-malware

What is Win.exe, How to remove Win.exe

Friday, November 20th, 2009

Win.exe is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: Win
Filename: Win.exe
Command: C:\WINDOWS\system32\config\Win.exe
Startup Type: win.ini
HijackThis Category: F3
HijackThis Line:

F3 – REG:win.ini: run=C:\WINDOWS\system32\config\Win.exe

Description: trojan downloader

How to remove: use HijackThis + Malwarebytes` Anti-malware

What is winupdate86.exe, How to remove winupdate86.exe

Friday, November 20th, 2009

winupdate86.exe is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: winupdate86
Filename: winupdate86.exe
Registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | winupdate86.exe

Command: C:\WINDOWS\system32\winupdate86.exe
Startup Type: HKLM->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKLM\..\Run: [winupdate86.exe] C:\WINDOWS\system32\winupdate86.exe

Combofix/RSIT Line:

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“winupdate86.exe”=C:\WINDOWS\system32\winupdate86.exe

Description: trojan agent that installed with winhelper86.dll, winlogon86.exe trojans and Advanced Virus Remover (rogue antispyware program) and shows fake spyware alerts

How to remove: use these winhelper86.dll, winupdate86.exe, winlogon86.exe removal instructions.

What is wow64main.exe, How to remove wow64main.exe

Tuesday, November 17th, 2009

wow64main.exe is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: wow64main
Filename: wow64main.exe
Registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | wow64main.exe

Command: %Temp%\wow64main.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKCU\..\Run: [wow64main.exe] %Temp%\wow64main.exe

Combofix/RSIT Line:

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“wow64main.exe”=%Temp%\wow64main.exe [2009-10-25 1146880]

Description: trojan that installed with rogue antispyware programs

How to remove: use HijackThis + Malwarebytes` Anti-malware

What is tdidis32.sys, How to remove tdidis32.sys

Friday, November 13th, 2009

tdidis32.sys is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: tdidis32
Filename: tdidis32.sys
Command: C:\WINDOWS\system32\tdidis32.sys
Startup Type: driver
Combofix/RSIT Line:

S1 tdidis32.sys;tdidis32.sys; \??\C:\WINDOWS\system32\tdidis32.sys []

Description: trojan agent also known as Rootkit.Win32.Pakes

How to remove: use SUPERAntiSpyware

What is logon.exe, How to remove logon.exe

Wednesday, November 4th, 2009

logon.exe is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: logon
Filename: logon.exe
Startup Type: system.ini
HijackThis Category: F2
HijackThis Line:

F2 – REG:system.ini: Shell=Explorer.exe logon.exe

Description: trojan that installed with a rogue antispyware program

How to remove: use HijackThis + Malwarebytes` Anti-malware

What is sysnet.dll, How to remove sysnet.dll

Wednesday, November 4th, 2009

This is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: sysnet
Filename: sysnet.dll
Registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad | SysNet

Command: C:\Documents and Settings\All Users\Microsoft AData\sysnet.dll
CLSID: {13E9115E-2CB0-4CAB-91D0-507E9368ED1B}
Startup Type: ShellServiceObjectDelayLoad
HijackThis Category: O21
HijackThis Line:

O21 – SSODL: SysNet – {13E9115E-2CB0-4CAB-91D0-507E9368ED1B} – C:\Documents and Settings\All Users\Microsoft AData\sysnet.dll

RSIT Line:

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
SysNet – {13E9115E-2CB0-4CAB-91D0-507E9368ED1B} – C:\Documents and Settings\All Users\Microsoft AData\sysnet.dll

Description: trojan agent that installed with a rogue antispyware program

How to remove: use HijackThis + Malwarebytes` Anti-malware

What is csrss1.dll, How to remove csrss1.dll

Wednesday, November 4th, 2009

csrss1.dll is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: csrss1
Filename: csrss1.dll
Registry key:

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Csrss

Command: c:\windows\system32\csrss1.dll
Startup Type: Winlogon Notify
HijackThis Category: O20
HijackThis Line:

O20 – Winlogon Notify: Csrss – c:\windows\system32\csrss1.dll

Combofix/RSIT Line:

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Csrss]
2009-10-20 17:31 139264 —-a-w- c:\windows\system32\csrss1.dll

Description: unknown trojan

How to remove: use HijackThis + Malwarebytes` Anti-malware

What is calc.dll, How to remove calc.dll

Monday, October 26th, 2009

calc.dll is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: calc
Filename: calc.dll
Registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | calc

Command: C:\WINDOWS\system32\calc.dll
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKLM\..\Run: [calc] rundll32.exe C:\WINDOWS\system32\calc.dll,_IWMPEvents@0

Combofix/RSIT Line:

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“calc”=rundll32.exe C:\WINDOWS\system32\calc.dll,_IWMPEvents@0

Description: a trojan that installed with ntuser.dll trojan and scandisk.dll trojan

How to remove: use HijackThis and Malwarebytes` Anti-malware or Kaspersky virus removal tool

What is ntuser.dll, How to remove ntuser.dll

Monday, October 26th, 2009

ntuser.dll is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: ntuser
Filename: ntuser.dll
Registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | calc

Command: %UserProfile%\ntuser.dll
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKCU\..\Run: [calc] rundll32.exe C:\DOCUME~1\username\ntuser.dll,_IWMPEvents@0

Combofix/RSIT Line:

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“calc”=rundll32.exe C:\DOCUME~1\username\ntuser.dll,_IWMPEvents@0

Description: a trojan that installed with scandisk.dll trojan

How to remove: use HijackThis and use Malwarebytes` Anti-malware or use Kaspersky virus removal tool