Solved! Use SVCHESTS.EXE (Trojan Agent) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

SVCHESTS.EXE – Trojan Agent removal

FileMD5Virus Alias
SVCHESTS.EXE d2d2298922503979c666d0db5931c3ac Trojan Agent
SVCHESTS.EXE d2d2298922503979c666d0db5931c3ac Trojan (Suspicious File)
SVCHESTS.EXE d2d2298922503979c666d0db5931c3ac Trojan Generic
SVCHESTS.EXE d2d2298922503979c666d0db5931c3ac Trojan Eldorado
SVCHESTS.EXE d2d2298922503979c666d0db5931c3ac Trojan Buzus
SVCHESTS.EXE d2d2298922503979c666d0db5931c3ac Trojan Siggen

SVCHESTS.EXE size: 55296 bytes
SVCHESTS.EXE hash: D2D2298922503979C666D0DB5931C3AC

Created files:

%WinDir%\system\svchests.exe
%SysDir%\fishpe.sys
%Temp%\596D45.dmp

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\FishPeShield\Type: 01000000
HKLM\System\CurrentControlSet\Services\FishPeShield\Start: 03000000
HKLM\System\CurrentControlSet\Services\FishPeShield\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\FishPeShield\DisplayName: Fish PE Shield Driver
HKLM\System\CurrentControlSet\Services\FishPeShield\ImagePath: %WinDir%\System32\fishpe.sys

Detected by UnHackMe:

SVCHESTS.EXE
Default location: %WinDir%\SYSTEM\SVCHESTS.EXE

Dropper information:
MD5: c5bf717aabd2548307dd2393b3b387f3
File size: 110569 bytes

Leave a Reply