DLLHST3G.EXE – Trojan Small

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

DLLHST3G.EXE – Trojan Small removal

FileMD5Virus Alias
DLLHST3G.EXE 04305bc91bab2c35ba79ffdb327191e6 Trojan Small
DLLHST3G.EXE 04305bc91bab2c35ba79ffdb327191e6 Trojan Generic
DLLHST3G.EXE 04305bc91bab2c35ba79ffdb327191e6 Trojan Eldorado
DLLHST3G.EXE 04305bc91bab2c35ba79ffdb327191e6 Trojan Downloader
DLLHST3G.EXE 04305bc91bab2c35ba79ffdb327191e6 Trojan Agent
DLLHST3G.EXE 04305bc91bab2c35ba79ffdb327191e6 Trojan Crypt

DLLHST3G.EXE size: 472064 bytes
DLLHST3G.EXE hash: 04305BC91BAB2C35BA79FFDB327191E6

Created files:

%WinDir%\System\csrss.exe
%WinDir%\System\dllhst3g.exe
%WinDir%\System\spoolsv.exe
%UserProfile%\Local Settings\Application Data\esentutl.exe
%TEMP%\Twain002.Mtx
%AllUsersProfile%\mqtgsvc.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\Csrss: %WinDir%\System\csrss.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\DllHost3g: %WinDir%\System\dllhst3g.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\Spooler: %WinDir%\System\spoolsv.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\EseNtUtl: %Local AppData%\esentutl.exe

Detected by UnHackMe:

DLLHST3G.EXE
Default location: %WinDir%\SYSTEM\DLLHST3G.EXE

Dropper information:
MD5: 04305bc91bab2c35ba79ffdb327191e6
File size: 472064 bytes

Leave a Reply