Attention: This is a VIRUS! From initial analysis I can say the following: That helper dll is a trojan which opens a backdoor with a number of APIs, allowing remote code execution and other tasks It also intercepts authentication and forwards the intercepted credentials to a control server I tries to eliminate traces of existence by cleaning the corresponding lines from the log files.  There's also the ability to delete logs completely It appears that the inf