How to remove wow_helper.exe.vir

wow_helper.exe.vir

The module wow_helper.exe.vir has been detected as Adware.SweetIM

wow_helper.exe.vir
MD5: 9f1ae66d7954fe2e0909a5ebc6b94798
Size: 65 KB
First Published: 2017-05-21 04:03:13 (6 years ago)
Latest Published: 2024-04-13 23:02:02 (2 days ago)
Status: Adware.SweetIM (on last analysis)
Analysis Date: 2024-04-13 23:02:02 (2 days ago)
%appdata%\360se6\application
%localappdata%\host app service\engine
%localappdata%\zetagamesviewer
%localappdata%\pokki\engine
%localappdata%\sweetlabs app platform\engine
%commonappdata%\ubar\ubar\v1.8.0.6
%programfiles%\hextech repair tool
%localappdata%\pokki\engine-old
%commonappdata%\ubar\ubar\modules\cef
%localappdata%\nichrome\application\30.0.1599.101
wow_helper.exe
wow_helper (1).exe
12.5%
8.3%
6.6%
6.0%
5.9%
5.1%
4.4%
3.5%
3.5%
3.0%
2.8%
2.5%
2.4%
2.1%
1.7%
1.6%
1.6%
1.5%
1.4%
1.2%
1.2%
1.2%
1.2%
1.1%
1.1%
1.1%
1.0%
0.8%
0.8%
0.8%
0.7%
0.7%
0.6%
0.6%
0.6%
0.6%
0.5%
0.5%
0.4%
0.4%
0.4%
0.3%
0.3%
0.3%
0.3%
0.3%
0.2%
0.2%
0.2%
0.2%
0.2%
0.2%
0.2%
0.2%
0.2%
0.2%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
Windows 10 70.1%
Windows 8.1 19.9%
Windows 7 8.9%
Windows 8 0.8%
Windows XP 0.2%
Windows Vista 0.1%
Subsystem: Windows GUI
PE Type: pe
OS Bitness: 64
Image Base: 0x0000000140000000
Entry Address: 0x00002430

PE Sections:

Name Size of data MD5
.text 43008 8e7c76fe1a2a876d0a32486a79f31a0f
.rdata 14848 8a4d6dae1ffb513a498e6af6231f35d8
.data 4608 0b23b61333e0a07d35f0e3c64a30157b
.pdata 3072 233243fa1e81ba801b629c80ce96b5b9
.rsrc 512 b3b723b59be19386e7c203cce186aeeb

More information:

Download GridinSoft Anti-Malware - Removal tool for wow_helper.exe.vir