rs32net.exe is TrojanDropper


This is a harmful program.

remove It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program.
If that does not help, then ask us for help in the Spyware removal forum.

Name: rs32net
Filename: rs32net.exe
Registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | rs32net

Command: C:\WINDOWS\System32\rs32net.exe
Startup Type: HKCU->Run
HijackThis Category: O4
HijackThis Line:

O4 – HKCU\..\Run: [rs32net] C:\WINDOWS\System32\rs32net.exe

Combofix/RSIT Line:

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“rs32net”=C:\WINDOWS\System32\rs32net.exe

Description: rs32net.exe is TrojanDropper, also known as Mal/Pushdo-A [Sophos], Trojan.Pandex [Symantec], FakeAlert-AG.gen.c [McAfee],

How to remove: Use HijackThis

Leave a Reply