NPCLSRV.EXE – Trojan Agent

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

NPCLSRV.EXE – Trojan Agent removal

FileMD5Virus Alias
NPCLSRV.EXE 3cc53df4dac31b6dbb5cf1dcccd1ed2c Trojan Agent
NPCLSRV.EXE 3cc53df4dac31b6dbb5cf1dcccd1ed2c Trojan SuspiciousFile
NPCLSRV.EXE 3cc53df4dac31b6dbb5cf1dcccd1ed2c Trojan Generic

NPCLSRV.EXE size: 102400 bytes
NPCLSRV.EXE hash: 3CC53DF4DAC31B6DBB5CF1DCCCD1ED2C

Created files:

%Program Files%\NPAVAdminClient\FileSndr.dll
%Program Files%\NPAVAdminClient\GenSender.dll
%Program Files%\NPAVAdminClient\LstnCmd.dll
%Program Files%\NPAVAdminClient\NpClInst.exe
%Program Files%\NPAVAdminClient\NpClSrv.exe
%Program Files%\NPAVAdminClient\ProcessCmd.dll
%Program Files%\NPAVAdminClient\RegMgmt.dll
%Program Files%\NPAVAdminClient\RegSilen.exe
%Program Files%\NPAVAdminClient\RptParse.dll
%TEMP%\AgentInstaller\AgentInstaller\NpClInst.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\NPClSrv\Type: 10010000
HKLM\System\CurrentControlSet\Services\NPClSrv\Start: 02000000
HKLM\System\CurrentControlSet\Services\NPClSrv\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\NPClSrv\DisplayName: NPAV Agent Service
HKLM\System\CurrentControlSet\Services\NPClSrv\ImagePath: %Program Files%\NPAVAdminClient\NpClSrv.exe

Detected by UnHackMe:

NPCLSRV.EXE
Default location: %PROGRAM FILES%\NPAVADMINCLIENT\NPCLSRV.EXE

Dropper information:
MD5: 5c292575b2ac12d2ac6c5fa3a4e47621
File size: 495616 bytes

Leave a Reply