What is sys64_nov.exe, How to remove sys64_nov.exe
Sunday, November 29th, 2009This is a harmful program.
It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. |
Name: sys64_nov
Filename: sys64_nov.exe
Registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | sys64_nov
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | sys64_nov
Command:
%WinDir%\system32\sys64_nov.exe
%UserProfile%\sys64_nov.exe
Startup Type: HKLM->Run, HKCU->Run
HijackThis Category: O4
HijackThis Line:
O4 – HKLM\..\Run: [sys64_nov] C:\WINDOWS\system32\sys64_nov.exe
O4 – HKCU\..\Run: [sys64_nov] C:\Documents and Settings\user\sys64_nov.exe
DDS Line:
mRun: [sys64_nov] C:\WINDOWS\system32\sys64_nov.exe
uRun: [sys64_nov] C:\Documents and Settings\user\sys64_nov.exe
Combofix/RSIT Line:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“sys64_nov”=C:\WINDOWS\system32\sys64_nov.exe
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“sys64_nov”=C:\Documents and Settings\user\sys64_nov.exe
Description: trojan agent that installed with rogue antispyware programs
How to remove: use HijackThis + Malwarebytes` Anti-malware