SCFNHO.EXE – Trojan Swisyn

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

SCFNHO.EXE – Trojan Swisyn removal

FileMD5Virus Alias
SCFNHO.EXE 78969434808b8789cb354993ece6214c Trojan Swisyn
SCFNHO.EXE 78969434808b8789cb354993ece6214c Trojan Comame
SCFNHO.EXE 78969434808b8789cb354993ece6214c Trojan Agent

SCFNHO.EXE size: 455635 bytes
SCFNHO.EXE hash: 78969434808B8789CB354993ECE6214C

Created files:

%Program Files%\DNSProtectSupport\svchost.exe
%Program Files%\DNSProtectSupport\svchost.exe.bak
%TEMP%\fMZYSyU.exe
%TEMP%\kcTeZFWGEJVy.exe
%TEMP%\scFNho.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\DNSProtectSupport\Type: 10000000
HKLM\System\CurrentControlSet\Services\DNSProtectSupport\Start: 02000000
HKLM\System\CurrentControlSet\Services\DNSProtectSupport\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\DNSProtectSupport\ImagePath: %Program Files%\DNSProtectSupport\svchost.exe

Detected by UnHackMe:

SCFNHO.EXE
Default location: %TEMP%\SCFNHO.EXE

Dropper information:
MD5: 4423641e4f44a3d1f0bd761d2b04d33c
File size: 474960 bytes

Leave a Reply