SVCHQST.EXE – Backdoor Bifrose

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

SVCHQST.EXE – Backdoor Bifrose removal

FileMD5Virus Alias
SVCHQST.EXE 8091e3ad38e6515d045b336aa49bd18a Backdoor Bifrose
SVCHQST.EXE 8091e3ad38e6515d045b336aa49bd18a Trojan CI
SVCHQST.EXE 8091e3ad38e6515d045b336aa49bd18a Worm Autoit
SVCHQST.EXE 8091e3ad38e6515d045b336aa49bd18a Trojan Agent
SVCHQST.EXE 8091e3ad38e6515d045b336aa49bd18a Trojan Scar

SVCHQST.EXE size: 334608 bytes

Created files:

%SysDir%\svchqst.exe
%TEMP%\nldoktg
%TEMP%\susnwvk

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\WinDC\Type: 10010000
HKLM\System\CurrentControlSet\Services\WinDC\Start: 02000000
HKLM\System\CurrentControlSet\Services\WinDC\DisplayName: Windows DNS Client
HKLM\System\CurrentControlSet\Services\WinDC\ImagePath: “%WinDir%\System32\svchqst.exe”

Detected by UnHackMe:

SVCHQST.EXE
Default location: %SYSDIR%\SVCHQST.EXE

Leave a Reply