Solved! Use NETVMDBSVC.EXE (Backdoor Hupigon) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

NETVMDBSVC.EXE – Backdoor Hupigon removal

File MD5 Virus Alias
NETVMDBSVC.EXE b3564b4945da6a7f60a553a7e058e205 Backdoor Hupigon
NETVMDBSVC.EXE b3564b4945da6a7f60a553a7e058e205 Trojan SuspiciousFile
NETVMDBSVC.EXE b3564b4945da6a7f60a553a7e058e205 Trojan PAM
NETVMDBSVC.EXE b3564b4945da6a7f60a553a7e058e205 Trojan CI
NETVMDBSVC.EXE b3564b4945da6a7f60a553a7e058e205 Trojan Agent
NETVMDBSVC.EXE b3564b4945da6a7f60a553a7e058e205 Trojan Delf

NETVMDBSVC.EXE size: 190976 bytes
NETVMDBSVC.EXE hash: B3564B4945DA6A7F60A553A7E058E205

Created files:

%SysDir%\netvmdbsvc.dll
%SysDir%\netvmdbsvc.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\NETVMService\Type: 10010000
HKLM\System\CurrentControlSet\Services\NETVMService\Start: 02000000
HKLM\System\CurrentControlSet\Services\NETVMService\DisplayName: NETVM DataBase Connection Service
HKLM\System\CurrentControlSet\Services\NETVMService\ImagePath: %WinDir%\System32\svchost.exe -k netsvcs
HKLM\System\CurrentControlSet\Services\NETVMService\Description: NETVM DataBase Connection Service
HKLM\System\CurrentControlSet\Services\NETVMService\SBIE_Win32ExitCode: 02000000
HKLM\System\CurrentControlSet\Services\NETVMService\Parameters\ServiceDll: 43003A005C00570049004E0044004F00570053005C00730079007300740065006D00330032005C006E006500740076006D00640062007300760063002E0064006C006C000000

Detected by UnHackMe:

NETVMDBSVC.EXE
Default location: %SYSDIR%\NETVMDBSVC.EXE

Dropper information:
MD5: b3564b4945da6a7f60a553a7e058e205
File size: 190976 bytes

Leave a Reply