Remove Winvestigator. Description and removal instructions

 
Title: Winvestigator

Type: Keyloggers
Severity scale:Winvestigator severity is 68  (68 / 100)
 
Winvestigator is a commercial key logging tool that tracks user activity, records keystrokes, regularly takes screenshots and logs web sites visited. Gathered data can be sent to a configurable e-mail address. Winvestigator must be manually installed. It automatically runs on every Windows startup.

This keylogger violates privacy and security of those who has it on board; however, it can be used for legitimate reasons such as tracking children online habits. Unfortunately, it can also be employed by malicious attackers to steal bank accounts details, logins and passwords, personal data and other sensitive information.


Related files: loaddll.exe, winvestigator.exe, wv.exe, loaddll.dll, spoder.dll, sysninit.dll, syswvh.dll, syswvmail.dll, syswvnt.dll, syswvwin.dll, wvres.dll, wvh.dll

Winvestigator properties:
• Takes and sends out screenshots of user activity
• Sends out logs by FTP or email
• Logs keystrokes
• Hides from the user
• Stays resident in background

Automatic Winvestigator removal:

remover for Winvestigator

Winvestigator manual removal:

Kill processes:
loaddll.exe, winvestigator.exe, wv.exe
Delete registry values:
HKEY_CLASSES_ROOT\.send
HKEY_CLASSES_ROOT\wvfile
HKEY_CURRENT_USER\Software\Tropsoft
HKEY_LOCAL_MACHINE\SOFTWARE\Tropsoft
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\wvsys
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Winvestigator
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\loaddll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\wv.exe
Unregister DLLs:
loaddll.dll spoder.dll sysninit.dll syswvh.dll syswvmail.dll syswvnt.dll syswvwin.dll wvres.dll wvh.dll

Delete files:
loaddll.exe, winvestigator.exe, wv.exe, loaddll.dll, spoder.dll, sysninit.dll, syswvh.dll, syswvmail.dll, syswvnt.dll, syswvwin.dll, wvres.dll, wvh.dll
Delete directories:
C:\Program Files\wv
Misc:
Exact file location:
wv.exe, wvh.dll, wvres.dll - C:\Program Files\wv
loaddll.exe, loaddll.dll, spooder.dll, sysninit.dll, syswvh.dll, syswvmail.dll, syswvnt.dll, syswvwin.dll - C:\Windows or C:\Winnt

Other programs to remove Winvestigator:

• Malwarebytes Anti Malware - Review - Download
• Malwarebytes Anti Malware - Review - Download
• Windows Defender - Review - Download

Information added: 19/03/04
Information updated: 14/11/08

Additional resources related to Winvestigator:

Attention: If you know or you have a website or page about Winvestigator removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Winvestigator parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:


Comments from visitors:


1. by Robo. 2008-11-13 14:11:50
I found none of the above files. Still Winvestigator is back after reboot.

2. re: comment about Winvestigator by prp. 2005-02-24 05:02:08
not found any of the above but still have winvestigator on my system

3. by Good Boy. 2004-03-02 21:15:49
Used to be Keyboard Monitor 3.0


Latest spyware news:
Similar parasites:
Related discussions: