Trojan . Trojan.wtfhe (Summary)
Software Name: Trojan.wtfhe
Product Name: Trojan.wtfhe
Mass mailing email worm which collects email addresses from infected computers and distributes itself using emails. It can allow a remote user access to an infected computer. It also prevents access to certain security related websites.
Some of the Trojan.Trojan.wtfhe components
are listed below. The list is compiled as a reference. The list might
not be complete and it doesn't represent instructions for manual removal.
We DO NOT recommend manual removal. Incorrect removal
of certain software might make your computer unstable or even unusable.
Removal of adware component might affect the related ad-supported software.
If you suspect that you have an unwanted instance of Trojan.wtfhe
installed on your computer we recommend a free
audit of your system with INAC Anti Spyware.
Trojan.wtfhe might create following folders (and inject its files inside
Trojan.wtfhe might create following files (some of the files might be
loaded in memory while the software is running):
Trojan.wtfhe is often accompanied by the following tracking cookies:
Trojan.wtfhe might create following registry keys (and inject subkeys
Trojan.wtfhe might create following registry values:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole|RealPlayer Ath Check
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|RealPlayer Ath Check
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices|RealPlayer Ath Check
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa|RealPlayer Ath Check
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa|RealPlayer Ath Check
- HKEY_USERS\*\Software\Microsoft\OLE|RealPlayer Ath Check
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Run|RealPlayer Ath Check
- HKEY_USERS\*\SYSTEM\CurrentControlSet\Control\Lsa|RealPlayer Ath Check
Trojan.wtfhe might create registry values with following data:
Trojan.wtfhe might insert following entries in the HOSTS file:
here to scan your computer for Trojan.wtfhe free of charge