
By Jim
Updated on Wednesday, August 11th, 2010
Wireshark is a trusted name in network analysis. They have several tools that cater to this but they do not make antivirus software. So it should be quite obvious that Wireshark Antivirus is a fake application. If you’ve paid for the upgraded version of this program, go ahead and dispute the charges to have it reversed.
While this application might look legitimate from the outside, it does not do any real virus cleaning and scanning even once you’ve paid for its supposed upgrade. It also does a lot of tinkering with your system where the results can range from mildly annoying to downright dangerous. It changes the settings of your browser, shows advertisements and connects to the internet by itself. It also blocks lots of apps such that you won’t even be able to use Notepad while it is around.
Removing rogue malware like this can be tricky but fortunately there are tools specifically designed for this. You might be thinking of just sending your computer to a technician or worse, buy a new PC. It doesn’t have to go that far though. Take our advice and just follow our simple and easy guide so you can blast away this app for good.

- Download Spyware Doctor and save to your Desktop (if you cannot download then bookmark this page and skip to Step 3 to restore your internet)
- Rename the file iexplorer.exe
- Restart your Computer in Safe Mode with Networking (keep tapping F8 while your system boots up)
- Launch Internet Explorer, click on Tools and then Internet Options.
- Click on the Connections tab and select LAN Options
- Uncheck the box Use a Proxy Server For Your LAN and click OK
- Launch iexplorer.exe (Spyware Doctor)
- Update Malware Definitions and click Start Scan
- Click the Fix Checked button and remove Wireshark Antivirus
Remove Wireshark Antivirus In Minutes With an Automatic Removal Tool.
Simply Click “Start Download Now!” to Begin!

Symptoms Of Infection
- Your computer is acting slow. Wireshark Antivirus slows down your system significantly. This includes starting up, shutting down, playing games, and surfing the web.
- You are getting pestered with pop ups. Wireshark Antivirus infects your registry and uses it to launch annoying pop up ads out of nowhere.
- Searches are redirected or your homepage and desktop are settings are changed. This is a symptom of a very serious Wireshark Antivirus infection.
Dangers Of Infection
Viruses like Wireshark Antivirus will infect your registry and other important system files. If the infection is not treated it can cause a complete collapse of your system.
![]()
Some Wireshark Antivirus infections contain spyware and keyloggers which can be used to record sensitive data like passwords, credit card, bank account, and social security numbers. The longer you allow the infection to fester, the greater the chance of identity fraud.
How To Remove Infection Manually
Uninstall Wireshark Antivirus Processes
alggui.exe
svchost.exe
dbsinit.exe
ccsmn.exe
ccsrr.exe
wpp.exe
Delete Wireshark Antivirus Files
c:\Program Files\adc_w32.dll
c:\Program Files\alggui.exe
c:\Program Files\extra1.dat
c:\Program Files\extra2.dat
c:\Program Files\nuar.old
c:\Program Files\skynet.dat
c:\Program Files\svchost.exe
c:\Program Files\wp3.dat
c:\Program Files\wp4.dat
c:\Program Files\scdata
c:\Program Files\scdata\dbsinit.exe
c:\Program Files\scdata\wispex.html
c:\Program Files\scdata\images
c:\Program Files\scdata\images\i1.gif
c:\Program Files\scdata\images\i2.gif
c:\Program Files\scdata\images\i3.gif
c:\Program Files\scdata\images\j1.gif
c:\Program Files\scdata\images\j2.gif
c:\Program Files\scdata\images\j3.gif
c:\Program Files\scdata\images\jj1.gif
c:\Program Files\scdata\images\jj2.gif
c:\Program Files\scdata\images\jj3.gif
c:\Program Files\scdata\images\l1.gif
c:\Program Files\scdata\images\l2.gif
c:\Program Files\scdata\images\l3.gif
c:\Program Files\scdata\images\pix.gif
c:\Program Files\scdata\images\t1.gif
c:\Program Files\scdata\images\t2.gif
c:\Program Files\scdata\images\Thumbs.db
c:\Program Files\scdata\images\up1.gif
c:\Program Files\scdata\images\up2.gif
c:\Program Files\scdata\images\w1.gif
c:\Program Files\scdata\images\w11.gif
c:\Program Files\scdata\images\w2.gif
c:\Program Files\scdata\images\w3.jpg
c:\Program Files\scdata\images\word.doc
c:\Program Files\scdata\images\wt1.gif
c:\Program Files\scdata\images\wt2.gif
c:\Program Files\scdata\images\wt3.gif
c:\Program Files\Sysinternals Antivirus
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn.exe
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn151.acf
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn151.ltd
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn151.lti
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn151_0.acb
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn151_0.aci
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsmn151_0.mt
%UserProfile%\Application Data\Microsoft\Internet Explorer\ccsrr.exe
%UserProfile%\Application Data\Microsoft\Internet Explorer\lleod150
%UserProfile%\Application Data\Microsoft\Internet Explorer\wmharun.log
%UserProfile%\Application Data\Microsoft\Internet Explorer\wmrun.log
%UserProfile%\Start Menu\Programs\Wireshark Antivirus
%UserProfile%\Start Menu\Programs\Wireshark Antivirus\Wireshark Antivirus.lnk
Remove Wireshark Antivirus Registry Files
HKEY_CLASSES_ROOTCLSID{149256D5-E103-4523-BB43-2CFB066839D6}
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{149256D5-E103-4523-BB43-2CFB066839D6}
HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesAdbUpd
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun “novavapp”
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun “novavappr”
Popular Search Terms
Remove Wireshark Antivirus
Delete Wireshark Antivirus
Uninstall Wireshark Antivirus
How to get rid of Wireshark Antivirus
How to remove Wireshark Antivirus
Wireshark Antivirus removal
Remove WiresharkAntivirus
WiresharkAntivirus removal
Wireshark-Antivirus-Live
Warning! If Spyware Doctor is blocked by the virus then run your system in safe mode and try again. To do this reboot your system and tap F8 repeatedly as your computer starts up. Then run Spyware Doctor as normal. If this doesn’t work try renaming the Spyware Doctor EXE file.
Posted under Fake Antispyware | No Comments
