SVCHOST.EXE – Trojan Delf

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

SVCHOST.EXE – Trojan Delf removal

File MD5 Virus Alias
SVCHOST.EXE 7c47a76d89d8126eb03b7be62ee1439d Trojan Delf
SVCHOST.EXE 7c47a76d89d8126eb03b7be62ee1439d Suspicious File
SVCHOST.EXE 7c47a76d89d8126eb03b7be62ee1439d Trojan Generic
SVCHOST.EXE 7c47a76d89d8126eb03b7be62ee1439d Trojan Eldorado
SVCHOST.EXE 7c47a76d89d8126eb03b7be62ee1439d Trojan Downloader
SVCHOST.EXE 7c47a76d89d8126eb03b7be62ee1439d Trojan Agent

SVCHOST.EXE size: 194560 bytes
SVCHOST.EXE hash: 7C47A76D89D8126EB03B7BE62EE1439D

Created files:

C:\Documents and Settings\LocalService\Local Settings\Application Data\sLT.exf
%SysDir%\drivers\svchost.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Host Generic Process\Type: 10010000
HKLM\System\CurrentControlSet\Services\Host Generic Process\Start: 02000000
HKLM\System\CurrentControlSet\Services\Host Generic Process\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\Host Generic Process\DisplayName: Host Generic Process for Win32 Services
HKLM\System\CurrentControlSet\Services\Host Generic Process\ImagePath: %WinDir%\System32\drivers\svchost.exe

Detected by UnHackMe:

SVCHOST.EXE
Default location: %SYSDIR%\DRIVERS\SVCHOST.EXE

Dropper information:
MD5: 7c47a76d89d8126eb03b7be62ee1439d
File size: 194560 bytes

Leave a Reply