Solved! Use NTHID.SYS (Trojan Agent) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

NTHID.SYS – Trojan Agent removal

File MD5 Virus Alias
NTHID.SYS 4a15af4ff018f73e7b734589cd50ea89 Trojan Agent
NTHID.SYS 4a15af4ff018f73e7b734589cd50ea89 Trojan Generic
NTHID.SYS 4a15af4ff018f73e7b734589cd50ea89 Trojan Downloader
NTHID.SYS 4a15af4ff018f73e7b734589cd50ea89 Worm Autorun
NTHID.SYS 4a15af4ff018f73e7b734589cd50ea89 Trojan Small

NTHID.SYS size: 5008 bytes
NTHID.SYS hash: 4A15AF4FF018F73E7B734589CD50EA89

Created files:

%TEMP%\NtHid.sys
%Temp%\Expor.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\bits\Start: 02000000
HKLM\System\CurrentControlSet\Services\NtHid\Type: 01000000
HKLM\System\CurrentControlSet\Services\NtHid\Start: 03000000
HKLM\System\CurrentControlSet\Services\NtHid\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\NtHid\DisplayName: NtHid
HKLM\System\CurrentControlSet\Services\NtHid\ImagePath: %TEMP%\NtHid.sys

Detected by UnHackMe:

NTHID.SYS
Default location: %TEMP%\NTHID.SYS

Dropper information:
MD5: 9d24233808b767ba5ca09985a4f77b2d
File size: 352256 bytes

Leave a Reply