SVCHOST.EXE – Backdoor Plugx

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

SVCHOST.EXE – Backdoor Plugx removal

File MD5 Virus Alias
SVCHOST.EXE a8dd5d448023771934461c7825b458c3 Backdoor Plugx
SVCHOST.EXE a8dd5d448023771934461c7825b458c3 Trojan Artemis
SVCHOST.EXE a8dd5d448023771934461c7825b458c3 Trojan Generic
SVCHOST.EXE a8dd5d448023771934461c7825b458c3 Trojan Downloader
SVCHOST.EXE a8dd5d448023771934461c7825b458c3 Trojan Graftor
SVCHOST.EXE a8dd5d448023771934461c7825b458c3 Trojan Agent

SVCHOST.EXE size: 297489 bytes
SVCHOST.EXE hash: A8DD5D448023771934461C7825B458C3

Created files:

C:\programdata\Svchost.exe
%AllUsersProfile%\MC\Mc.exe
%AllUsersProfile%\MC\McUtil.dll
%Temp%\RarSFX0\Mc.exe
%Temp%\RarSFX0\McUtil.dll

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Macfee MC\Type: 10010000
HKLM\System\CurrentControlSet\Services\Macfee MC\Start: 02000000
HKLM\System\CurrentControlSet\Services\Macfee MC\DisplayName: Macfee MC Server
HKLM\System\CurrentControlSet\Services\Macfee MC\ImagePath: %AllUsersProfile%\MC\Mc.exe

Detected by UnHackMe:

SVCHOST.EXE
Default location: C:\PROGRAMDATA\SVCHOST.EXE

Dropper information:
MD5: 2385b332637dd37e4e5c79a1fed46171
File size: 370622 bytes

Leave a Reply