SVCHOST.EXE – Trojan Delf

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

SVCHOST.EXE – Trojan Delf removal

File MD5 Virus Alias
SVCHOST.EXE ea78eb273f0c633b8a0a86f386f2310b Trojan Delf
SVCHOST.EXE ea78eb273f0c633b8a0a86f386f2310b Trojan Generic
SVCHOST.EXE ea78eb273f0c633b8a0a86f386f2310b Trojan Eldorado
SVCHOST.EXE ea78eb273f0c633b8a0a86f386f2310b Trojan Downloader
SVCHOST.EXE ea78eb273f0c633b8a0a86f386f2310b Trojan Agent
SVCHOST.EXE ea78eb273f0c633b8a0a86f386f2310b Trojan Scar

SVCHOST.EXE size: 194560 bytes
SVCHOST.EXE hash: EA78EB273F0C633B8A0A86F386F2310B

Created files:

C:\Documents and Settings\LocalService\Local Settings\Application Data\sLT.exf
%SysDir%\drivers\svchost.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\System Information N321\Type: 10010000
HKLM\System\CurrentControlSet\Services\System Information N321\Start: 02000000
HKLM\System\CurrentControlSet\Services\System Information N321\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\System Information N321\DisplayName: System Information N321
HKLM\System\CurrentControlSet\Services\System Information N321\ImagePath: %WinDir%\System32\drivers\svchost.exe

Detected by UnHackMe:

SVCHOST.EXE
Default location: %SYSDIR%\DRIVERS\SVCHOST.EXE

Dropper information:
MD5: ea78eb273f0c633b8a0a86f386f2310b
File size: 194560 bytes

Leave a Reply