WINDOWSHELPER.EXE - Dangerous

%APPDATA%\WINDOWSHELPER.EXE

Jeff's Story:

My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.

I sought a solution on the Internet and discovered your product and tried out the trial.

You quickly found the rootkit and SAVED my PC!

I haven't had any problems since, and I'm extremely grateful.

Manual removal instructions:

%appdata%\windowshelper.exe
We suggest you to remove WINDOWSHELPER.EXE from your computer as soon as possible.
WINDOWSHELPER.EXE is known as: Worm.MSIL [Ikarus].
MD5 of WINDOWSHELPER.EXE = 1F604FB596F6A62F34D5DA3C34CF7751
WINDOWSHELPER.EXE size is 9216 bytes.
Full path on a computer: %APPDATA%\WINDOWSHELPER.EXE
Related Files:
%APPDATA%\ACEY168ROX
%APPDATA%\FRAMEWORK\WINUPDATE.BAT
%APPDATA%\FRAMEWORK\WORKER\CURLLIB.DLL
%APPDATA%\FRAMEWORK\WORKER\GPL-2.0.TXT
%APPDATA%\FRAMEWORK\WORKER\HSTART.EXE
%APPDATA%\FRAMEWORK\WORKER\KERNELS\POCLBM\BFIPATCHER.PY
%APPDATA%\FRAMEWORK\WORKER\KERNELS\POCLBM\KERNEL.CL
%APPDATA%\FRAMEWORK\WORKER\KERNELS\POCLBM\__INIT__.PY
%APPDATA%\FRAMEWORK\WORKER\LIBEAY32.DLL
%APPDATA%\FRAMEWORK\WORKER\LIBSASL.DLL
%APPDATA%\FRAMEWORK\WORKER\LICENSE.TXT
%APPDATA%\FRAMEWORK\WORKER\MSCOREE.DLL
%APPDATA%\FRAMEWORK\WORKER\OPENLDAP.DLL
%APPDATA%\FRAMEWORK\WORKER\PHOENIX.EXE
%APPDATA%\FRAMEWORK\WORKER\SSLEAY32.DLL
%APPDATA%\FRAMEWORK\WORKER\WININIIT.EXE
%APPDATA%\FRAMEWORK\WORKER\XXMKLINK.EXE
%APPDATA%\POOFER.EXE
%TEMP%\WINHOST.EXE
%APPDATA%\WINDOWSHELPER.EXE
%TEMP%\33548.EXE
%TEMP%\IGFXTRAY.EXE
%TEMP%\TEXTT.EXE
%TEMP%\WININI.EXE

Remove WINDOWSHELPER.EXE now!