hidn2.exe - Dangerous

hidn2.exe

Jeff's Story:

My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.

I sought a solution on the Internet and discovered your product and tried out the trial.

You quickly found the rootkit and SAVED my PC!

I haven't had any problems since, and I'm extremely grateful.

Manual removal instructions:

hidn2.exe
hidn2.exe is rootkit W32/Bagle-KJ.
hidn2.exe is used to hide files, processes and registry.
hidn2.exe is a kernel mode rootkit.
hidn2.exe spreads by e-mail.
hidn2.exe tries to terminate antiviral programs installed on a user computer.
Related files:
\Application Data\hidn\hidn2.exe
\Application Data\hidn\m_hook.sys
m_hook.sys is created new system driver.
Added to registry:
HKLM\SYSTEM\CurrentControlSet\Services\m_hook
Adds the value:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
drv_st_key

to the Windows startup registry keys.
Rootkit attempts to delete the following registry entry into Safe Mode:
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network

Remove hidn2.exe now!