Click on screenshot to zoom
Danger level 7
Type: Trojans
Common infection symptoms:
  • Connects to the internet without permission
  • Slow internet connection
  • Slow Computer
Other mutations known as:

Trojan-PSW.WOW

Trojan-PSW.WOW is the latest Trojan infections reeking only havoc to infected systems.

Trojan-PSW.WOW, being a Trojan infection tends to be installed onto a computer via a security exploits, and without the user’s awareness. Trojan-PSW.WOW drops and loads a password stealing component on the infected system and tries to steal account information from it. It also tries to steal information that is required to access certain online banks' and online payment systems' websites.

Systems infected with the Trojan-PSW.WOW parasite, also known as Trojan-PSW.WOW, have been investigated, and the findings show that Trojan-PSW.WOW tends to display the following characteristics:

• Downloads/requests other files from Internet.
• Creates a start-up registry entry
• Packed with a packer that is known to be used by malware (e.g. to complicate threat analysis or detection)
• Contains characteristics of an identified security risk.

Trojan-PSW.WOW is particularly damaging to a computer system, once it has fully embedded itself within the PC’s system, therefore it is given a high priority security risk status by many computer analysts.

The fact that Trojan-PSW.WOW can easily enter any PC system via security exploits and flaws, most times without the user’s interaction, means that it is that much easier for Trojan-PSW.WOW to enter the system and ensure the system’s security is immensely compromised.

Once Trojan-PSW.WOW is installed it may begin to download and install additional malware onto the infiltrated system, which may in turn cause serious issues and render the infected computer useless.

All financial and personal data may be at serious risk of being stolen, should a computer system have Trojan-PSW.WOW.

Trojan-PSW.WOW tends to allow a remote attacker to gain access to all personal information, which is highly capable of resulting in identity theft.

Risks which may affect the PC’s system functions include: the opening of illicit network connections, the use of polymorphic tactics to self-mutate, the disabling of already installed security software, modification of system files, and not forgetting the installation of additional malware.

It is highly recommended to make use of a reliable and legitimate anti-spyware application, to remove Trojan-PSW.WOW and all its components from the infected computer system.

Download Spyware Removal Tool to Remove* Trojan-PSW.WOW
  • Quick & tested solution for Trojan-PSW.WOW removal.
  • 100% Free Scan for Windows
disclaimer

How to manually remove Trojan-PSW.WOW

Files associated with Trojan-PSW.WOW infection:

msmxjchn.dll
nodlogin.exe
wm1dap.dll
yxcsbhlp.dll
tavo1.dll
ltsolvrz.dll
dzmydf.dll
WinSoft3.DLL
533931MM.DLL
WebPaper.exe
csrns.exe
msuqddft.dll
msejfzrl.dll
WINSvr64.exe
ctfmon.exe
sichost.exe
jsdb.dll
10417sys.dll
08223b03.dll
122b901e.dll
2ef0d734.dll
49400W.exe
49400M.exe
533931M.exe
338448L.exe
55551.dll
7F1C46C1BD7F.dll
fgjk4wvb.dll
326xxx.dll
03518usc.dll
kavo.exe
kavo1.dll
msosfmsq00.dll
amvo.exe
winsvr32.exe
4138kou.dll
3272xxx.dll
msosdrop00.dll
mfchlp64.exe
tciocp64.exe
ttFKKFKK1065.dll
msosjtio00.dll
zywmdime.dll
yuiabct.exe
wintunpce.exe
dat5.tmp
svchosts.exe
wyrsdj.dll
fjyjy.dll
iexplorer.exe
kavo0.dll
yebaep.dll
fsrgeb.dll
winlogun.exe
tdfhex.dll
jfdses.dll
sgdewg.dll
dndsaf.dll
zgxfdx.dll
wzcfsw.dll
zAPWgSjGrSpdsE4.fon
liser.dll
pcidisk.sys
RhdwE8NYdbqQ.dll
fmsjhif.dll
yuiabct.dll
iexplore.exe
msasvc.exe
ZCfgSvc.exe
Slave.exe
gina_x86.dll
helper.dll
otrewe1.dll
mkfght0.dll
rttrwq.exe
cvsdfw.exe
z9gNwvuVDpyQqHSu.fon
isadisk.sys
antit.dll
hyrteas0.dll
load[2].exe
1[1].exe
WowInitcode.dll
mf[1].exe
vshost.exe
testabd.exe
2235001327.dll

Trojan-PSW.WOW DLL's to remove:

WinSoft3.DLL
533931MM.DLL
msmxjchn.dll
wm1dap.dll
yxcsbhlp.dll
tavo1.dll
ltsolvrz.dll
dzmydf.dll
msuqddft.dll
msejfzrl.dll
jsdb.dll
10417sys.dll
08223b03.dll
122b901e.dll
2ef0d734.dll
55551.dll
7F1C46C1BD7F.dll
fgjk4wvb.dll
326xxx.dll
03518usc.dll
kavo1.dll
msosfmsq00.dll
4138kou.dll
3272xxx.dll
msosdrop00.dll
ttFKKFKK1065.dll
msosjtio00.dll
zywmdime.dll
wyrsdj.dll
fjyjy.dll
kavo0.dll
yebaep.dll
fsrgeb.dll
tdfhex.dll
jfdses.dll
sgdewg.dll
dndsaf.dll
zgxfdx.dll
wzcfsw.dll
liser.dll
RhdwE8NYdbqQ.dll
fmsjhif.dll
yuiabct.dll
gina_x86.dll
helper.dll
otrewe1.dll
mkfght0.dll
antit.dll
hyrteas0.dll
WowInitcode.dll
2235001327.dll

Trojan-PSW.WOW processes to kill:

SearchSettingsProtection.exe
nodlogin.exe
WebPaper.exe
csrns.exe
WINSvr64.exe
ctfmon.exe
sichost.exe
49400W.exe
49400M.exe
533931M.exe
338448L.exe
kavo.exe
amvo.exe
winsvr32.exe
mfchlp64.exe
tciocp64.exe
yuiabct.exe
wintunpce.exe
svchosts.exe
iexplorer.exe
winlogun.exe
iexplore.exe
msasvc.exe
ZCfgSvc.exe
Slave.exe
rttrwq.exe
cvsdfw.exe
load[2].exe
1[1].exe
mf[1].exe
vshost.exe
testabd.exe

Remove Trojan-PSW.WOW registry entries:

HKEY_CURRENT_USERSOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN ttool
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ amva
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ anhtaas
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ ertyuop
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Explorer
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ kava
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN SysCom
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWSNT\CURRENTVERSION\WINDOWS\APPINIT_DLLS\ AppInit_DLLs
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWSNT\CURRENTVERSION\WINLOGON\USERINIT\ userinit
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00D13CE9-1879-41bd-B8A3-EA3CB1BD01BC}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Fyj
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ HKLM
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ jsg8jfgfdfhfhf
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ mfchlp64
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Subsystem Monitor
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ systeminfors
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ tciocp64
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ WINSvr64
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ WinSysM
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ WinSysW
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ yuiabct
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\isadisk
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Microsoft authenticate service
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\pcidisk
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RA Server
RUNNING PROGRAM\Explorer.EXE
RUNNING PROGRAM\winlogon.exe
RUNNING PROGRAM\wintunpce.exe
Disclaimer

Post comment — WE NEED YOUR OPINION!

Comment:
Name:
Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.