About Alex Nightwatcher

Malware Hunter.

Find more about me on:

Here are my most recent posts

Author Archives: Alex Nightwatcher

About Alex Nightwatcher

Malware Hunter.

Remove nav.brotlab.net virus (How to remove nav.brotlab.net from Chrome, Mozilla Firefox, IE)

Remove Ads by nav.brotlab.net nav.brotlab.net ads are displayed as large blocks of content and imagery, intrusive pop-ups, gutter ads, distracting click-bait and suggestive content that is usually unrelated to the content of the Web site you are browsing. Ads by nav.brotlab.net While many Web surfers tend to dislike nav.brotlab.net ads for being intrusive and suggestive, […]
More…

Remove "Ads by 11598763487076930564" virus in 5 minutes!

11598763487076930564 is reported as Win32:PUP-gen (potentially unwanted program). I suggest you to remove 11598763487076930564 from your PC as soon as possible! Tried to remove 11598763487076930564? Cannot completely delete 11598763487076930564, because it gets back? Uninstall 11598763487076930564, kill 11598763487076930564 process using Task Manager, delete 11598763487076930564 folder, remove 11598763487076930564 registry key, get rid of 11598763487076930564 scheduled task, disable […]
More…

Remove PLAYSTV_LAUNCHER.EXE malware

Be careful! Full path on computer: %PROGRAM FILES%\RAPTR INC\PLAYSTV\PLAYSTV_LAUNCHER.EXE The file PLAYSTV_LAUNCHER.EXE is malware related. You must delete the file PLAYSTV_LAUNCHER.EXE immediately! Delete the file PLAYSTV_LAUNCHER.EXE without delay! Kill the process PLAYSTV_LAUNCHER.EXE and remove PLAYSTV_LAUNCHER.EXE from the Windows startup. PLAYSTV_LAUNCHER.EXE is related to: DangerousObject.Multi.Gen, PLAYSTV_LAUNCHER.EXE. Autostart registry keys: HKLM\SOFTWARE\CLASSES\EXEFILE\SHELL\OPEN\%PROGRAM FILES%\RAPTR INC\PLAYSTV\PLAYSTV_LAUNCHER.EXE: “PLAYS.TV VIDEO RECORDER BY […]
More…

Remove PLAYSTV.EXE malware

Be careful! Full path on computer: %PROGRAM FILES%\RAPTR INC\PLAYSTV\PLAYSTV.EXE The file PLAYSTV.EXE is malware related. You must delete the file PLAYSTV.EXE immediately! Delete the file PLAYSTV.EXE without delay! Kill the process PLAYSTV.EXE and remove PLAYSTV.EXE from the Windows startup. PLAYSTV.EXE is related to: DangerousObject.Multi.Gen, PLAYSTV.EXE. Autostart registry keys: HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\PLAYSTV\DISPLAYICON: “”%PROGRAM FILES%\RAPTR INC\PLAYSTV\PLAYSTV.EXE”” HKLM\Software\Microsoft\DirectDraw\MostRecentApplication\Name: “playstv.exe” Related […]
More…

What is vulkaninfo.exe? Should I remove Vulkaninfo.exe malware?

What is vulkaninfo.exe? There are a lot of files detected with name Vulkaninfo.exe. The most popular are: C:\Program Files (x86)\VulkanRT\1.0.3.0\Vulkaninfo.exe. c:\windows\system32\Vulkaninfo.exe. VULKANINFO.EXE (64-bit file) MD5: B14FF3A750CDBA33378C4A549B585DFD SHA1: 870A26EC FCF37677 D07661B8 10A6383B EA0F857B SHA256: 746365cb68f65643cd97a4bd6ea54f52087e611634a19e9e911e274ab609a03d File Size: 45 848 File names: vulkaninfo-1-1-0-3-1.exe vulkaninfo-$_0_.exe vulkaninfo.exe vulkaninfo.exe vulkaninfo.exe vulkaninfo-1-1-0-3-1.exe vulkaninfo.exe Signer: LunarG VirusTotal: 0/56 https://virustotal.com/en/file/746365cb68f65643cd97a4bd6ea54f52087e611634a19e9e911e274ab609a03d/analysis/ This file is […]
More…

Remove TINY.DAT malware

Be careful! Full path on computer: %PROGRAM FILES%\CHEAT ENGINE 6.4\TINY.DAT TINY.DAT is High Risk Trojan. TINY.DAT must be removed immediately! It can used for stealing bank information and users passwords. TINY.DAT can download malicious software from hacker’s web sites. TINY.DAT allow someone to connect to your computer remotely. TINY.DAT is related to: Trojan.Generic.cetn, TINY.DAT. Related […]
More…

Remove WPSHOSTHELPER.DLL adware!

Be careful! Full path on computer: %APPDATA%\IQIYI VIDEO\LSTYLE\WPSHOSTHELPER.DLL The file WPSHOSTHELPER.DLL was tested and considered as Adware. Adware displays pop-up ads in order to generate revenue for its author. WPSHOSTHELPER.DLL shows pop-up ads or text ads or advertising banners. Sometimes WPSHOSTHELPER.DLL displays coupons banners for sites you are visiting. The banners are really annoying and […]
More…

Remove FUSION.DLL malware

Be careful! Full path on computer: %TEMP%\IS-CKDFV.TMP\FUSION.DLL The file FUSION.DLL is malware related. You must delete the file FUSION.DLL immediately! Delete the file FUSION.DLL without delay! Kill the process FUSION.DLL and remove FUSION.DLL from the Windows startup. FUSION.DLL is related to: PUA.Win32.FusionCore.D, FUSION.DLL. Related Files: %TEMP%\IS-CKDFV.TMP\CONFIG.INI %TEMP%\IS-CKDFV.TMP\CONFIG.RAR %TEMP%\IS-CKDFV.TMP\FUSION.DLL %TEMP%\IS-CKDFV.TMP\GCOUNTRY.DLL %TEMP%\IS-CKDFV.TMP\ITDOWNLOAD.DLL File Information FUSION.DLL: Virustotal = […]
More…

Remove "Ads by PMLS.DLL" virus in 5 minutes!

Be careful! Full path on computer: %TEMP%\{RANDOM}.TMP\PMLS.DLL What is PMLS.DLL? PMLS.DLL is reported and classified as a PUP (potentially unwanted program). PMLS.DLL installs as a plugin to your Web browser, intercepting your online activities, altering the content of Web pages and search results, and displaying an outstanding amount of highly invasive advertisements. PMLS.DLL cannot be […]
More…

Remove "Ads by MNRD.EXE" virus in 5 minutes!

Be careful! Full path on computer: %SYSTEMDRIVE%\USERDLL32\MNRD.EXE What is MNRD.EXE? MNRD.EXE is reported and classified as a PUP (potentially unwanted program). MNRD.EXE installs as a plugin to your Web browser, intercepting your online activities, altering the content of Web pages and search results, and displaying an outstanding amount of highly invasive advertisements. MNRD.EXE cannot be […]
More…

Remove zerohorizon.net virus (How to remove zerohorizon.net from Chrome, Mozilla Firefox, IE)

Remove Ads by zerohorizon.net zerohorizon.net ads are displayed as large blocks of content and imagery, intrusive pop-ups, gutter ads, distracting click-bait and suggestive content that is usually unrelated to the content of the Web site you are browsing. Ads by zerohorizon.net While many Web surfers tend to dislike zerohorizon.net ads for being intrusive and suggestive, […]
More…

Remove VIDEO.UI.EXE malware

The file VIDEO.UI.EXE is not a virus. The program VIDEO.UI.EXE is a system security tool. But the VIDEO.UI.EXE tool may be used to compromise computer security by the hacker. Use the VIDEO.UI.EXE file at your own risk! You can delete the VIDEO.UI.EXE program from your computer with problems. VIDEO.UI.EXE Information and Removal: VIDEO.UI.EXE is known […]
More…

Remove beap.gemini.yahoo.com virus (How to remove beap.gemini.yahoo.com from Chrome, Mozilla Firefox, IE

What is beap.gemini.yahoo.com and how dangerous it is? beap.gemini.yahoo.com is a malicious web site for your computer. beap.gemini.yahoo.com hijacks a browser’s new tab, search and home page. So, if you see beap.gemini.yahoo.com in your browser – your computer is under attack! Common symptoms of being infected by beap.gemini.yahoo.com are: Pop-up ads – a new web […]
More…

Remove us-ads.openx.net virus (How to remove us-ads.openx.net from Chrome, Mozilla Firefox, IE)

What is us-ads.openx.net and how dangerous it is? us-ads.openx.net is a malicious web site for your computer. us-ads.openx.net hijacks a browser’s new tab, search and home page. So, if you see us-ads.openx.net in your browser – your computer is under attack! Common symptoms of being infected by us-ads.openx.net are: Pop-up ads – a new web […]
More…

Remove s3-us-west-2.amazonaws.com virus (How to remove s3-us-west-2.amazonaws.com from Chrome, Mozilla Firefox, IE

What is s3-us-west-2.amazonaws.com and how dangerous it is? s3-us-west-2.amazonaws.com is a malicious web site for your computer. s3-us-west-2.amazonaws.com hijacks a browser’s new tab, search and home page. So, if you see s3-us-west-2.amazonaws.com in your browser – your computer is under attack! Common symptoms of being infected by s3-us-west-2.amazonaws.com are: Pop-up ads – a new web […]
More…

Remove HD for YouTube malware

HD for YouTube software is Win32:PUP-gen related. HD for YouTube (potentially unwanted program) is a program that may be unwanted for users. HD for YouTube may have one or more of unwanted features: spying user, advertising, search redirecting, or browser hijacking. HD for YouTube is often downloaded in a bundle with a useful program. Suggest […]
More…

What is BINGSVC.EXE? How to fix BINGSVC.EXE problem?

What is BINGSVC.EXE? The file BINGSVC.EXE is not a virus. The program BINGSVC.EXE is  a part of Microsoft Bing software. Antivirus testing: 0 / 68 Dangerous Status: Clean Malware Aliases:. MD5 of BINGSVC.EXE = 77C01F1850E55373280A1B865D824F58 BINGSVC.EXE size is 144008 bytes. Full path on a computer: C:\USERS\USER\APPDATA\LOCAL\MICROSOFT\BINGSVC\BINGSVC.EXE BINGSVC.EXE is registered as a system service. Do you […]
More…

Remove CSAW.EXE malware!

Full path on computer: %APPDATA%\MICROSOFT\CSAW.EXE MD5 = 85e3bb062d7dc76158410e34a0270086 CSAW.EXE software is Win32/64:PUP-gen related. CSAW.EXE (potentially unwanted program) is a program that may be unwanted for users. CSAW.EXE may have one or more of unwanted features: spying user, advertising, search redirecting, or browser hijacking. CSAW.EXE is often downloaded in a bundle with a useful program. Suggest […]
More…

Remove UPDATEFILES.EXE malware!

Full path on computer: %APPDATA%\BANK OF COMMUNICATIONS\BOCOM INTERNET BANKING WIZARD\INSTALL\2766035\UPDATEFILES.EXE MD5 = c509b8dea28de847a9ce70d35f6cbb2b UPDATEFILES.EXE software is Win32/64:PUP-gen related. UPDATEFILES.EXE (potentially unwanted program) is a program that may be unwanted for users. UPDATEFILES.EXE may have one or more of unwanted features: spying user, advertising, search redirecting, or browser hijacking. UPDATEFILES.EXE is often downloaded in a bundle […]
More…

Remove t.mookie1.com pop-up ads from Chrome, Firefox, Internet Explorer (Removal Guide: t.mookie1.com)

In this post I will tell you how to get rid of t.mookie1.com popup ads from Google Chrome, Mozilla Firefox, Internet Explorer. t.mookie1.com web site is detected as a threat. if you see this address t.mookie1.com in your browser – your web browser is hijacked! Common symptoms of t.mookie1.com: Pop-up ads. Unwanted messages. Search redirecting. […]
More…

Remove VDWFP64.SYS malware

The file VDWFP64.SYS is malware related. You must delete the file VDWFP64.SYS immediately! Delete the file VDWFP64.SYS without delay! Kill the process VDWFP64.SYS and remove VDWFP64.SYS from the Windows startup. VDWFP64.SYS Information and Removal: VDWFP64.SYS is known as: WFP driver Antivirus testing: 0 / 68Dangerous Status: CleanMalware Aliases:. MD5 of VDWFP64.SYS = 51B7F06BB9C6FA78BF1D1606D88834D5 VDWFP64.SYS size […]
More…

Remove ocsp.godaddy.com pop-up ads from Chrome, Firefox, Internet Explorer (Removal Guide: ocsp.godaddy.com)

In this post I will tell you how to get rid of ocsp.godaddy.com popup ads from Google Chrome, Mozilla Firefox, Internet Explorer. ocsp.godaddy.com web site is detected as a threat. if you see this address ocsp.godaddy.com in your browser – your web browser is hijacked! Common symptoms of ocsp.godaddy.com: Pop-up ads. Unwanted messages. Search redirecting. […]
More…

Remove SPVC64.DLL malware

SPVC64.DLL is High Risk Trojan. SPVC64.DLL must be removed immediately! It can used for stealing bank information and users passwords. SPVC64.DLL can download malicious software from hacker’s web sites. SPVC64.DLL allow someone to connect to your computer remotely. SPVC64.DLL Information and Removal: SPVC64.DLL is known as: Antivirus testing: 10 / 68Dangerous Status: AdwareMalware Aliases: TR/Trash.Gen […]
More…

Remove S2.symcb.com pop-up ads from Chrome, Firefox, Internet Explorer (Removal Guide: S2.symcb.com)

In this post I will tell you how to get rid of S2.symcb.com popup ads from Google Chrome, Mozilla Firefox, Internet Explorer. S2.symcb.com web site is detected as a threat. if you see this address S2.symcb.com in your browser – your web browser is hijacked! Common symptoms of S2.symcb.com: Pop-up ads. Unwanted messages. Search redirecting. […]
More…

Remove xfreeservice.com pop-up ads from Chrome, Firefox, Internet Explorer (Removal Guide: xfreeservice.com)

In this post I will tell you how to get rid of xfreeservice.com popup ads from Google Chrome, Mozilla Firefox, Internet Explorer. xfreeservice.com web site is detected as a threat. if you see this address xfreeservice.com in your browser – your web browser is hijacked! Common symptoms of xfreeservice.com: Pop-up ads. Unwanted messages. Search redirecting. […]
More…

How to easily remove STEAMWEBHELPER.EXE! Get Removal Guide

The file STEAMWEBHELPER.EXE is identified as a virus dropper. The dropper STEAMWEBHELPER.EXE is used for downloading and installing other malware, Trojans, viruses by the commands received from the Command Center. The file STEAMWEBHELPER.EXE loads into the computer memory and tries to connect to the dangerous web site. Usually the STEAMWEBHELPER.EXE dropper does not infect the […]
More…

Fixed! How to easily remove SPVC32LOADER.DLL adware!

We received the file SPVC32LOADER.DLL and detected thatSPVC32LOADER.DLL is not good. SPVC32LOADER.DLL is Adware. You should remove the file SPVC32LOADER.DLL. Kill the process SPVC32LOADER.DLL and remove SPVC32LOADER.DLL from Windows. SPVC32LOADER.DLL Information and Removal: SPVC32LOADER.DLL is known as: Search Protect by Conduit Antivirus testing: 18 / 68Dangerous Status: Potentially unwantedMalware Aliases: Riskware.SearchProtect Win32:SearchProtect-C [Adw] Adware.Win32.Conduit W32.Clodac3.Trojan […]
More…

Fixed! How to easily remove SPVC32.DLL adware!

We received the file SPVC32.DLL and detected thatSPVC32.DLL is not good. SPVC32.DLL is Adware. You should remove the file SPVC32.DLL. Kill the process SPVC32.DLL and remove SPVC32.DLL from Windows. SPVC32.DLL Information and Removal: SPVC32.DLL is known as: Search Protect by Conduit Antivirus testing: 14 / 68Dangerous Status: Potentially unwantedMalware Aliases: Win32:SearchProtect-C [Adw] Adware.Win32.Conduit W32.Clod90c.Trojan Adware.SearchProtect.Conduit.G […]
More…

SARA.EXE is Trojan Downloader

The file SARA.EXE is identified as the Trojan Program that is used for stealing bank information and users passwords. To delete SARA.EXE we suggest you should use UnHackMe: http://www.unhackme.com Malware Analysis of SARA.EXE Full path on a computer: %TEMP%\SARA.EXE Detected by UnHackMe: SARA.EXE Default location: %TEMP%\SARA.EXE Removal Results: Success Number of reboot: 1 SARA.EXE is […]
More…

HARRY POTTER AND THE DEATHLY HALLOWS PART 2-SKIDROW.COM is Trojan Hllw

The file HARRY POTTER AND THE DEATHLY HALLOWS PART 2-SKIDROW.COM is identified as the Trojan Program that is used for stealing bank information and users passwords. To delete HARRY POTTER AND THE DEATHLY HALLOWS PART 2-SKIDROW.COM we suggest you should use UnHackMe: http://www.unhackme.com Malware Analysis of HARRY POTTER AND THE DEATHLY HALLOWS PART 2-SKIDROW.COM Full […]
More…

TORRENT.VBE is Trojan Downloader

The file TORRENT.VBE is malware related. You must delete the file TORRENT.VBE immediately! Delete the file TORRENT.VBE without delay! Kill the process TORRENT.VBE and remove TORRENT.VBE from the Windows startup. Malware Analysis of TORRENT.VBE Full path on a computer: %APPDATA%\TORRENT.VBE Detected by UnHackMe: TORRENT.VBE Default location: %APPDATA%\TORRENT.VBE Removal Results: Success Number of reboot: 1 TORRENT.VBE […]
More…

KKK.VBS is Trojan Hosts

We checked some samples of KKK.VBS and detected the file KKK.VBS as threat. Remove the KKK.VBS file from your computer right now. Removal tool: http://www.unhackme.com Malware Analysis of KKK.VBS Full path on a computer: %TEMP%\1.TMP\KKK.VBS Detected by UnHackMe: KKK.VBS Default location: %TEMP%\1.TMP\KKK.VBS Removal Results: Success Number of reboot: 1 KKK.VBS is known as: Trojan.Hosts How […]
More…

AUTOPICO.EXE is Not a virus – Activator Windows 8

Analysis of AUTOPICO.EXE Full path on a computer: %PROGRAMFILES%\KMSPICO\AUTOPICO.EXE Detected by UnHackMe: AUTOPICO.EXE Default location: %PROGRAMFILES%\KMSPICO\AUTOPICO.EXE AUTOPICO.EXE is known as: Not a virus – Activator Windows 8 AUTOPICO.EXE hash: MD5: C63F33ACD45A7620E8FC678A585D18AF How to quickly detect AUTOPICO.EXE presence?  Files: %COMMONPROGRAMS%\KMSPICO\AUTOPICO.LNK %COMMONPROGRAMS%\KMSPICO\KMSPICO.LNK %COMMONPROGRAMS%\KMSPICO\LOG KMSPICO.LNK %COMMONPROGRAMS%\KMSPICO\UNINSTALL KMSPICO.LNK %PROGRAMFILES%\KMSPICO\AUTOPICO.EXE I use UnHackMe for cleaning ads and viruses from my […]
More…

WINZIX-2.3.0.0-SETUP.EXE is Trojan StartPage

The file WINZIX-2.3.0.0-SETUP.EXE is identified as the Trojan Program that is used for stealing bank information and users passwords. To delete WINZIX-2.3.0.0-SETUP.EXE we suggest you should use UnHackMe: http://www.unhackme.com Malware Analysis of WINZIX-2.3.0.0-SETUP.EXE Full path on a computer: \WINZIX-2.3.0.0-SETUP.EXE Detected by UnHackMe: WINZIX-2.3.0.0-SETUP.EXE Default location: \WINZIX-2.3.0.0-SETUP.EXE Removal Results: Success Number of reboot: 1 WINZIX-2.3.0.0-SETUP.EXE is […]
More…

CDCLIENT.DLL is Trojan Click

The file CDCLIENT.DLL can destroy your system, thus making the computer to work abnormally. CDCLIENT.DLL is a dangerous file. RemoveCDCLIENT.DLL from your computer immediately. Kill the process CDCLIENT.DLL and remove CDCLIENT.DLL from the Windows startup. Malware Analysis of CDCLIENT.DLL Full path on a computer: %TEMP%\214E81\CDCLIENT.DLL Detected by UnHackMe: CDCLIENT.DLL Default location: %TEMP%\214E81\CDCLIENT.DLL Removal Results: Success […]
More…

USERMODE.EXE is Trojan Siggen

The file USERMODE.EXE is identified as a virus dropper. The dropper USERMODE.EXE is used for downloading and installing other malware, Trojans, viruses by the commands received from the Command Center. The file USERMODE.EXE loads into the computer memory and tries to connect to the dangerous web site. Usually the USERMODE.EXE dropper does not infect the […]
More…

ATHEROSSVC.EXE is Trojan Downloader

The file ATHEROSSVC.EXE can destroy your system, thus making the computer to work abnormally. ATHEROSSVC.EXE is a dangerous file. RemoveATHEROSSVC.EXE from your computer immediately. Kill the process ATHEROSSVC.EXE and remove ATHEROSSVC.EXE from the Windows startup. Malware Analysis of ATHEROSSVC.EXE Full path on a computer: %PROGRAM FILES COMMON%\SYSTEM\ATHEROSSVC.EXE Detected by UnHackMe: ATHEROSSVC.EXE Default location: %PROGRAM FILES […]
More…

SPUPDATE.EXE is Trojan Downloader

We checked some samples of SPUPDATE.EXE and detected the file SPUPDATE.EXE as threat. Remove the SPUPDATE.EXE file from your computer right now. Removal tool: http://www.unhackme.com Malware Analysis of SPUPDATE.EXE Full path on a computer: %WINDIR%\SPUPDATE.EXE Detected by UnHackMe: SPUPDATE.EXE Default location: %WINDIR%\SPUPDATE.EXE Removal Results: Success Number of reboot: 1 SPUPDATE.EXE is known as: Trojan Downloader […]
More…

LAUNCHGTAIV.EXE is Trojan Generic

The file LAUNCHGTAIV.EXE is identified as a virus dropper. The dropper LAUNCHGTAIV.EXE is used for downloading and installing other malware, Trojans, viruses by the commands received from the Command Center. The file LAUNCHGTAIV.EXE loads into the computer memory and tries to connect to the dangerous web site. Usually the LAUNCHGTAIV.EXE dropper does not infect the […]
More…