HELPER.EXE – Backdoor Nitol

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

HELPER.EXE – Backdoor Nitol removal

FileMD5Virus Alias
HELPER.EXE 5fdf4c095d9a8200b11dd461e5fe514c Backdoor Nitol
HELPER.EXE 5fdf4c095d9a8200b11dd461e5fe514c Trojan Generic
HELPER.EXE 5fdf4c095d9a8200b11dd461e5fe514c Trojan Eldorado
HELPER.EXE 5fdf4c095d9a8200b11dd461e5fe514c Trojan Downloader
HELPER.EXE 5fdf4c095d9a8200b11dd461e5fe514c Trojan Siggen
HELPER.EXE 5fdf4c095d9a8200b11dd461e5fe514c Trojan Agent

HELPER.EXE size: 33280 bytes
HELPER.EXE hash: 5FDF4C095D9A8200B11DD461E5FE514C

Created files:

%SysDir%\Helper.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Windows Helper My Test 1.0\Type: 10000000
HKLM\System\CurrentControlSet\Services\Windows Helper My Test 1.0\Start: 02000000
HKLM\System\CurrentControlSet\Services\Windows Helper My Test 1.0\DisplayName: Windows Helper My Test Server 1.0
HKLM\System\CurrentControlSet\Services\Windows Helper My Test 1.0\ImagePath: %WinDir%\System32\Helper.exe
HKLM\System\CurrentControlSet\Services\Windows Helper My Test 1.0\Description: This is Windows Helper My Helper Server 1.0

Detected by UnHackMe:

HELPER.EXE
Default location: %SYSDIR%\HELPER.EXE

Dropper information:
MD5: 5fdf4c095d9a8200b11dd461e5fe514c
File size: 33280 bytes

Leave a Reply