Solved! Use SVCHOST.EXE (Trojan Agent) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

SVCHOST.EXE – Trojan Agent removal

File MD5 Virus Alias
SVCHOST.EXE 9c22405237db925127c4d41bde57967f Trojan Agent
SVCHOST.EXE 9c22405237db925127c4d41bde57967f Trojan Exception.gen.101
SVCHOST.EXE 9c22405237db925127c4d41bde57967f Trojan Generic
SVCHOST.EXE 9c22405237db925127c4d41bde57967f Trojan MulDrop4
SVCHOST.EXE 9c22405237db925127c4d41bde57967f Trojan Eldorado
SVCHOST.EXE 9c22405237db925127c4d41bde57967f Trojan Downloader

SVCHOST.EXE size: 253952 bytes
SVCHOST.EXE hash: 9C22405237DB925127C4D41BDE57967F

Created files:

%Program Files Common%\Microsoft Shared\WindowsUpdate\svchost.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\WSFilter\Type: 10000000
HKLM\System\CurrentControlSet\Services\WSFilter\Start: 02000000
HKLM\System\CurrentControlSet\Services\WSFilter\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\WSFilter\DisplayName: Windows Filter Foundation Framework
HKLM\System\CurrentControlSet\Services\WSFilter\ImagePath: %Program Files Common%\Microsoft Shared\WindowsUpdate\svchost.exe -s -k -netsvc

Detected by UnHackMe:

SVCHOST.EXE
Default location: %PROGRAM FILES COMMON%\MICROSOFT SHARED\WINDOWSUPDATE\SVCHOST.EXE

Dropper information:
MD5: 9c22405237db925127c4d41bde57967f
File size: 253952 bytes

Leave a Reply