SCVHOST.EXE – Trojan CoinMiner

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

SCVHOST.EXE – Trojan CoinMiner removal

FileMD5Virus Alias
SCVHOST.EXE aa59b15f83b24d0c709cde556fb4f842 Trojan CoinMiner
SCVHOST.EXE aa59b15f83b24d0c709cde556fb4f842 Trojan WS.Reputation
SCVHOST.EXE aa59b15f83b24d0c709cde556fb4f842 Trojan SuspiciousFile
SCVHOST.EXE aa59b15f83b24d0c709cde556fb4f842 Worm AMN
SCVHOST.EXE aa59b15f83b24d0c709cde556fb4f842 Trojan Siggen

SCVHOST.EXE size: 460800 bytes
SCVHOST.EXE hash: AA59B15F83B24D0C709CDE556FB4F842

Created files:

%Program Files%\%appdata%\winlogon\chp.exe
%Program Files%\%appdata%\winlogon\diablo121016.cl
%Program Files%\%appdata%\winlogon\diakgcn121016.cl
%Program Files%\%appdata%\winlogon\libblkmaker-0.1-0.dll
%Program Files%\%appdata%\winlogon\libblkmaker_jansson-0.1-0.dll
%Program Files%\%appdata%\winlogon\libcurl-4.dll
%Program Files%\%appdata%\winlogon\libjansson-4.dll
%Program Files%\%appdata%\winlogon\libusb-1.0.dll
%Program Files%\%appdata%\winlogon\miner.php
%Program Files%\%appdata%\winlogon\pdcurses.dll
%Program Files%\%appdata%\winlogon\phatk121016.cl
%Program Files%\%appdata%\winlogon\poclbm121016.cl
%Program Files%\%appdata%\winlogon\pthreadGC2.dll
%Program Files%\%appdata%\winlogon\scrypt121016.cl
%Program Files%\%appdata%\winlogon\scvhost.exe
%Program Files%\%appdata%\winlogon\zlib1.dll

Detected by UnHackMe:

SCVHOST.EXE
Default location: %PROGRAM FILES%\%APPDATA%\WINLOGON\SCVHOST.EXE

Dropper information:
MD5: 81cf9ac9feb9393ffb66960d1175153d
File size: 600414 bytes

Leave a Reply