DARKCODERSC.EXE – Trojan Vilsel

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

DARKCODERSC.EXE – Trojan Vilsel removal

FileMD5Virus Alias
DARKCODERSC.EXE 0af2b172d1be363dae67ea327588f958 Trojan Vilsel
DARKCODERSC.EXE 0af2b172d1be363dae67ea327588f958 Trojan Generic
DARKCODERSC.EXE 0af2b172d1be363dae67ea327588f958 Trojan Eldorado
DARKCODERSC.EXE 0af2b172d1be363dae67ea327588f958 Trojan Downloader
DARKCODERSC.EXE 0af2b172d1be363dae67ea327588f958 Trojan Delf
DARKCODERSC.EXE 0af2b172d1be363dae67ea327588f958 Trojan Scar

DARKCODERSC.EXE size: 664064 bytes
DARKCODERSC.EXE hash: 0AF2B172D1BE363DAE67EA327588F958

Created files:

%WinDir%\windows\DarkCoderSc.exe

Autostart registry keys:

HKLM\Software\Microsoft\Active Setup\Installed Components\{88RT8-U084T6Q-B9Q96-PDG1KN-1CKWCELQV}\StubPath: %WinDir%\windows\DarkCoderSc.exe Restart
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\IAm-DarkCoderSc: %WinDir%\windows\DarkCoderSc.exe
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: Explorer.exe,%WinDir%\windows\DarkCoderSc.exe
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit: %WinDir%\System32\userinit.exe,%WinDir%\windows\DarkCoderSc.exe
HKLM\System\CurrentControlSet\Services\svchost.exe\Type: 10000000
HKLM\System\CurrentControlSet\Services\svchost.exe\Start: 02000000
HKLM\System\CurrentControlSet\Services\svchost.exe\DisplayName: svchost
HKLM\System\CurrentControlSet\Services\svchost.exe\ImagePath: %WinDir%\windows\DarkCoderSc.exe

Detected by UnHackMe:

DARKCODERSC.EXE
Default location: %WinDir%\WINDOWS\DARKCODERSC.EXE

Dropper information:
MD5: 0af2b172d1be363dae67ea327588f958
File size: 664064 bytes

Leave a Reply