I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:
Free DownloadFully Functional 30-day Trial. No credit card is required.
Reviews. EULA. Privacy Policy. Uninstall.
WMHLPR.DLL – Backdoor Bifrose removal
File | MD5 | Virus Alias |
---|---|---|
WMHLPR.DLL | 86d9ca56f94c07811ca5ea00073a95d4 | Backdoor Bifrose |
WMHLPR.DLL size: 66240 bytes
WMHLPR.DLL hash: 86D9CA56F94C07811CA5EA00073A95D4
Created files:
%TEMP%\2vns3s.dll
%TEMP%\33\cdn.dll
%TEMP%\33\cdnaux.dll
%TEMP%\33\cdncmd.dll
%TEMP%\33\cdncol.dll
%TEMP%\33\cdndet.dll
%TEMP%\33\cdndrag.dll
%TEMP%\33\cdnforie.dll
%TEMP%\33\cdnins.dll
%TEMP%\33\cdnns.dll
%TEMP%\33\cdnprh.dll
%TEMP%\33\cdnprot.sys
%TEMP%\33\cdnsign.dll
%TEMP%\33\cdntdns.dll
%TEMP%\33\cdntran.sys
%TEMP%\33\cdnuc.exe
%TEMP%\33\cdnunins.exe
%TEMP%\33\cdnup.exe
%TEMP%\33\cdnuplib.dll
%TEMP%\33\client.dll
%TEMP%\33\idnconv.dll
%TEMP%\33\iesrch.dll
%TEMP%\33\imaoe.dll
%TEMP%\33\rbtnhtm.cab
%TEMP%\33\setup.exe
%TEMP%\33\wmhlpr.dll
%TEMP%\cijbdswwkb
%TEMP%\r6qqyl.dll
Autostart registry keys:
HKLM\System\CurrentControlSet\Services\cijbdsw\Type: 01000000
HKLM\System\CurrentControlSet\Services\cijbdsw\Start: 03000000
HKLM\System\CurrentControlSet\Services\cijbdsw\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\cijbdsw\DisplayName: cijbdsw
HKLM\System\CurrentControlSet\Services\cijbdsw\ImagePath: %TEMP%\cijbdswwkb
Detected by UnHackMe:
WMHLPR.DLL
Default location: %TEMP%\33\WMHLPR.DLL
Dropper information:
MD5: 239831e7cf8be91748bd79c16f8eeea2
File size: 670208 bytes