What is netfilter2.sys?

netfilter2.sys is part of NetFilter SDK and developed by NetFilterSDK.com according to the netfilter2.sys version information.

netfilter2.sys's description is "NetFilter SDK TDI Hook Driver (WPP)"

netfilter2.sys is digitally signed by Spotflux, Inc.

netfilter2.sys is usually located in the 'C:\Windows\system32\drivers\' folder.

Some of the anti-virus scanners at VirusTotal detected netfilter2.sys.

If you have additional information about the file, please share it with the FreeFixer users by posting a comment at the bottom of this page.

Vendor and version information [?]

The following is the available information on netfilter2.sys:

PropertyValue
Product nameNetFilter SDK
Company nameNetFilterSDK.com
File descriptionNetFilter SDK TDI Hook Driver (WPP)
Internal namenetfilter2.sys
Original filenamenetfilter2.sys
Legal copyrightCopyright © 2013 NetFilterSDK.com
Product version1.4.3.1
File version1.4.3.1 built by: WinDDK

Here's a screenshot of the file properties when displayed by Windows Explorer:

Product nameNetFilter SDK
Company nameNetFilterSDK.com
File descriptionNetFilter SDK TDI Hook Driver (WPP)
Internal namenetfilter2.sys
Original filenamenetfilter2.sys
Legal copyrightCopyright © 2013 NetFilterSDK.com
Product version1.4.3.1
File version1.4.3.1 built by: WinDDK

Digital signatures [?]

netfilter2.sys has a valid digital signature.

PropertyValue
Signer nameSpotflux, Inc
Certificate issuer nameVeriSign Class 3 Code Signing 2010 CA
Certificate serial number787b156dbe2c603b1c32e7122cf5a030

VirusTotal report

8 of the 68 anti-virus programs at VirusTotal detected the netfilter2.sys file. That's a 12% detection rate.

ScannerDetection Name
Endgame malicious (high confidence)
ESET-NOD32 a variant of Win64/NetFilter.A potentially unsafe
Ikarus AdWare.SwiftBrowse
SUPERAntiSpyware Adware.NetFilter/Variant
TrendMicro PUA_BROWSEFOX.SMF1
TrendMicro-HouseCall PUA_BROWSEFOX.SMF1
Yandex Riskware.Agent!
Zillya Adware.Trioris.Win32.9
8 of the 68 anti-virus programs detected the netfilter2.sys file.

netfilter2.sys removal instructions

The instructions below shows how to remove netfilter2.sys with help from the FreeFixer removal tool. Basically, you install FreeFixer, scan your computer, check the netfilter2.sys file for removal, restart your computer and scan it again to verify that netfilter2.sys has been successfully removed. Here are the removal instructions in more detail:

  1. Download and install FreeFixer: http://www.freefixer.com/download.html
  2. Start FreeFixer and press the Start Scan button. The scan will finish in approximately five minutes.
    Screenshot of Start Scan button
  3. When the scan is finished, locate netfilter2.sys in the scan result and tick the checkbox next to the netfilter2.sys file. Do not check any other file for removal unless you are 100% sure you want to delete it. Tip: Press CTRL-F to open up FreeFixer's search dialog to quickly locate netfilter2.sys in the scan result.
    Red arrow point on the unwanted file
    C:\Windows\system32\drivers\netfilter2.sys
  4. Scroll down to the bottom of the scan result and press the Fix button. FreeFixer will now delete the netfilter2.sys file.
    Screenshot of Fix button
  5. Restart your computer.
  6. Start FreeFixer and scan your computer again. If netfilter2.sys still remains in the scan result, proceed with the next step. If netfilter2.sys is gone from the scan result you're done.
  7. If netfilter2.sys still remains in the scan result, check its checkbox again in the scan result and click Fix.
  8. Restart your computer.
  9. Start FreeFixer and scan your computer again. Verify that netfilter2.sys no longer appear in the scan result.
Please select the option that best describe your thoughts on the removal instructions given above








Free Questionnaires

Hashes [?]

PropertyValue
MD57208cd956d631713ce2a03bd7fb7e13b
SHA256d4e87ac564f33885ff2fbd7505feef44156fa6aed2363730b635e04e5c9e2836

What will you do with netfilter2.sys?

To help other users, please let us know what you will do with netfilter2.sys:



What did other users do?

The poll result listed below shows what users chose to do with netfilter2.sys. 74% have voted for removal. Based on votes from 113 users.

User vote results: There were 84 votes to remove and 29 votes to keep

NOTE: Please do not use this poll as the only source of input to determine what you will do with netfilter2.sys.

Comments

Please share with the other users what you think about this file. What does this file do? Is it legitimate or something that your computer is better without? Do you know how it was installed on your system? Did you install it yourself or did it come bundled with some other software? Is it running smoothly or do you get some error message? Any information that will help to document this file is welcome. Thank you for your contributions.

I'm reading all new comments so don't hesitate to post a question about the file. If I don't have the answer perhaps another user can help you.

ghostie writes

0 thumbs

hi, so I've got the same file/thing, whatever it is, but mine is registered under TitanArc instead. I've read the guide regarding Malware or legit, and from what I gather, you're saying if the file/thing has proper signature and details, it's most likely not a malware, is that right? So it's most likely legit, right? So mine is probably legit, wouldn't that be right? ._.
Anyway, recently through reimage pc repair online, it says that "...netfilter2.sys -- a variant of Win64/NetFilter. A potentially unsafe GrayWare [AdWare]/Win32.netfilter.a a.k.a Malware.Heuristic!ET(rdm)"
Should I be concerned? (because I don't understand computer jargon)
Anyway, thanks for your article!

# 15 Nov 2016, 20:50

Roger Karlsson writes

0 thumbs

@ghostie: Netfilter is a filter driver that can be used to modify and monitor network traffic. It can be used for good or bad.

http://netfiltersdk.com

I'm not familiar with TitanArc. Is it a company in Taiwan?

http://www.freefixer.com/library/publisher/TITAN%20ARC%20CORP.%20TAIWAN%20BRANCH%20(SAMOA)/

# 11 Dec 2016, 7:27

Martin Barr-David writes

0 thumbs

Netfiter2.sys is a PUP according to UnHackMe/RegRun by Greatis

# 28 Dec 2017, 5:48

lennie writes

0 thumbs

How do I remove Netfilter2.sys?
Len

# 30 Jul 2018, 7:41

Leave a reply