DLLHOST.EXE – Trojan Small

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

DLLHOST.EXE – Trojan Small removal

FileMD5Virus Alias
DLLHOST.EXE 05a930b7e1c559f96d5e26a122c376a2 Trojan Small
DLLHOST.EXE 05a930b7e1c559f96d5e26a122c376a2 Suspicious File
DLLHOST.EXE 05a930b7e1c559f96d5e26a122c376a2 Trojan Artemis
DLLHOST.EXE 05a930b7e1c559f96d5e26a122c376a2 Trojan Generic
DLLHOST.EXE 05a930b7e1c559f96d5e26a122c376a2 Trojan Eldorado
DLLHOST.EXE 05a930b7e1c559f96d5e26a122c376a2 Trojan Downloader

DLLHOST.EXE size: 465408 bytes
DLLHOST.EXE hash: 05A930B7E1C559F96D5E26A122C376A2

Created files:

%WinDir%\dllhst3g.exe
%WinDir%\System\dllhost.exe
%WinDir%\System32\drivers\rsvp.exe
%TEMP%\Twain002.Mtx
%AllUsersProfile%\dllhost.exe
%AllUsersProfile%\sessmgr.exe
%AllUsersProfile%\winlogon.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\DCOM: C:\DOCUME~1\ALLUSE~1\dllhost.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Sessmgr: C:\DOCUME~1\ALLUSE~1\sessmgr.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\WinLogon: %AllUsersProfile%\winlogon.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\DllHost3g: %WinDir%\dllhst3g.exe
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\load: %WinDir%\System\dllhost.exe

Detected by UnHackMe:

DLLHOST.EXE
Default location: %WinDir%\SYSTEM\DLLHOST.EXE

Dropper information:
MD5: 05a930b7e1c559f96d5e26a122c376a2
File size: 465408 bytes

Leave a Reply