Remove SPUTNIKHELPER.EXE malware
SPUTNIKHELPER.EXE Malware Removal Guide
Manual removal instructions:
Antivirus Report of SPUTNIKHELPER.EXE:
sputnikhelper.exe
Full path on a computer: %PROGRAM FILES%\MAIL.RU\SPUTNIK\SPUTNIKHELPER.EXE
Autostart registry keys:
HKLM\Software\Classes\AppID\SputnikHelper.EXE
HKLM\Software\Classes\AppID\SputnikHelper.EXE\AppID: "{BFD1C493-BE73-4660-9924-7C23CF34C11D}"
HKLM\SOFTWARE\CLASSES\CLSID\{D2D4C0D4-2E88-40D0-A0DB-B8F9AC388529}\LOCALSERVER32\: ""%PROGRAM FILES%\MAIL.RU\SPUTNIK\SPUTNIKHELPER.EXE""
HKLM\SOFTWARE\CLASSES\TYPELIB\{A6024453-8AD2-4424-8C4E-AB8BDE5506B9}\1.0\0\WIN32\: "%PROGRAM FILES%\MAIL.RU\SPUTNIK\SPUTNIKHELPER.EXE"
HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E0EB82CB-70CE-44C8-92BE-9771E59F15A3}\AppName: "SputnikHelper.exe"
HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SHAREDACCESS\PARAMETERS\FIREWALLPOLICY\FIREWALLRULES\{A512407A-9DBB-4795-BCA7-D6B4ADECC590}: "V2.10|ACTION=ALLOW|ACTIVE=TRUE|DIR=IN|PROTOCOL=6|PROFILE=PRIVATE|APP=%PROGRAM FILES%\MAIL.RU\SPUTNIK\SPUTNIKHELPER.EXE|NAME=%PROGRAM FILES%\MAIL.RU\SPUTNIK\SPUTNIKHELPER.EXE|"
HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SHAREDACCESS\PARAMETERS\FIREWALLPOLICY\FIREWALLRULES\{AA574E86-4F4F-4A8D-BD62-1089EFECAF86}: "V2.10|ACTION=ALLOW|ACTIVE=TRUE|DIR=IN|PROTOCOL=17|PROFILE=PRIVATE|APP=%PROGRAM FILES%\MAIL.RU\SPUTNIK\SPUTNIKHELPER.EXE|NAME=%PROGRAM FILES%\MAIL.RU\SPUTNIK\SPUTNIKHELPER.EXE|"
HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0EE79471-0936-434D-813B-2FFC16B636A9}\AppName: "SputnikHelper.exe"
Related Files:
%PROGRAM FILES%\MAIL.RU\GUARD\GUARDMAILRU.EXE
%PROGRAM FILES%\MAIL.RU\SPUTNIK\MAILRUSPUTNIK.DLL
%PROGRAM FILES%\MAIL.RU\SPUTNIK\MAILRUSPUTNIK.EXE
%PROGRAM FILES%\MAIL.RU\SPUTNIK\SPUTNIKFLASHPLAYER.EXE
%PROGRAM FILES%\MAIL.RU\SPUTNIK\SPUTNIKHELPER.EXE
SPUTNIKHELPER.EXE is High Risk Trojan.
SPUTNIKHELPER.EXE must be removed immediately!
It can used for stealing bank information and users passwords.
SPUTNIKHELPER.EXE can download malicious software from hacker's web sites.
SPUTNIKHELPER.EXE allow someone to connect to your computer remotely.
SPUTNIKHELPER.EXE is related to: PE:Trojan.RuMail!1.6574, SPUTNIKHELPER.EXE.
Virustotal = 1/55
MD5 = 14490061152C1DA331367203126BFEA2
File Size: 333008
File information:
OriginalFilename: SputnikHelper.exe
FileDescription: Mail.Ru IEBar helper object
InternalName: SputnikHelper.exe
CompanyName: Mail.Ru
FileVersion: 2, 4, 0, 270
LegalCopyright: Copyright c 2005 - 2011
SPUTNIKHELPER.EXE | Malware |
SPUTNIKHELPER.EXE | Dangerous |
SPUTNIKHELPER.EXE | High Risk |
Autostart registry keys:
HKLM\Software\Classes\AppID\SputnikHelper.EXE
HKLM\Software\Classes\AppID\SputnikHelper.EXE\AppID: "{BFD1C493-BE73-4660-9924-7C23CF34C11D}"
HKLM\SOFTWARE\CLASSES\CLSID\{D2D4C0D4-2E88-40D0-A0DB-B8F9AC388529}\LOCALSERVER32\: ""%PROGRAM FILES%\MAIL.RU\SPUTNIK\SPUTNIKHELPER.EXE""
HKLM\SOFTWARE\CLASSES\TYPELIB\{A6024453-8AD2-4424-8C4E-AB8BDE5506B9}\1.0\0\WIN32\: "%PROGRAM FILES%\MAIL.RU\SPUTNIK\SPUTNIKHELPER.EXE"
HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E0EB82CB-70CE-44C8-92BE-9771E59F15A3}\AppName: "SputnikHelper.exe"
HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SHAREDACCESS\PARAMETERS\FIREWALLPOLICY\FIREWALLRULES\{A512407A-9DBB-4795-BCA7-D6B4ADECC590}: "V2.10|ACTION=ALLOW|ACTIVE=TRUE|DIR=IN|PROTOCOL=6|PROFILE=PRIVATE|APP=%PROGRAM FILES%\MAIL.RU\SPUTNIK\SPUTNIKHELPER.EXE|NAME=%PROGRAM FILES%\MAIL.RU\SPUTNIK\SPUTNIKHELPER.EXE|"
HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SHAREDACCESS\PARAMETERS\FIREWALLPOLICY\FIREWALLRULES\{AA574E86-4F4F-4A8D-BD62-1089EFECAF86}: "V2.10|ACTION=ALLOW|ACTIVE=TRUE|DIR=IN|PROTOCOL=17|PROFILE=PRIVATE|APP=%PROGRAM FILES%\MAIL.RU\SPUTNIK\SPUTNIKHELPER.EXE|NAME=%PROGRAM FILES%\MAIL.RU\SPUTNIK\SPUTNIKHELPER.EXE|"
HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0EE79471-0936-434D-813B-2FFC16B636A9}\AppName: "SputnikHelper.exe"
Related Files:
%PROGRAM FILES%\MAIL.RU\GUARD\GUARDMAILRU.EXE
%PROGRAM FILES%\MAIL.RU\SPUTNIK\MAILRUSPUTNIK.DLL
%PROGRAM FILES%\MAIL.RU\SPUTNIK\MAILRUSPUTNIK.EXE
%PROGRAM FILES%\MAIL.RU\SPUTNIK\SPUTNIKFLASHPLAYER.EXE
%PROGRAM FILES%\MAIL.RU\SPUTNIK\SPUTNIKHELPER.EXE
SPUTNIKHELPER.EXE is High Risk Trojan.
SPUTNIKHELPER.EXE must be removed immediately!
It can used for stealing bank information and users passwords.
SPUTNIKHELPER.EXE can download malicious software from hacker's web sites.
SPUTNIKHELPER.EXE allow someone to connect to your computer remotely.
SPUTNIKHELPER.EXE is related to: PE:Trojan.RuMail!1.6574, SPUTNIKHELPER.EXE.
Virustotal = 1/55
MD5 = 14490061152C1DA331367203126BFEA2
File Size: 333008
File information:
OriginalFilename: SputnikHelper.exe
FileDescription: Mail.Ru IEBar helper object
InternalName: SputnikHelper.exe
CompanyName: Mail.Ru
FileVersion: 2, 4, 0, 270
LegalCopyright: Copyright c 2005 - 2011
Dmitry Sokolov:
I created UnHackMe in 2006 to fix the problem that antivioruses did not fix: detecting rootkits.
Since that time I work every day to fix the issues that antiviruses cannot.
If your antivirus have not helped you solve the problem, you should try UnHackMe.
We are a small company and you can ask me directly, if you have any questions.