Solved! Use SVCHOST.EXE (Trojan Delf) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

SVCHOST.EXE – Trojan Delf removal

File MD5 Virus Alias
SVCHOST.EXE e762f819a68a9faa065a3965b37b664c Trojan Delf
SVCHOST.EXE e762f819a68a9faa065a3965b37b664c Trojan Generic
SVCHOST.EXE e762f819a68a9faa065a3965b37b664c Trojan Eldorado
SVCHOST.EXE e762f819a68a9faa065a3965b37b664c Trojan Downloader
SVCHOST.EXE e762f819a68a9faa065a3965b37b664c Trojan QQPass
SVCHOST.EXE e762f819a68a9faa065a3965b37b664c Trojan Agent

SVCHOST.EXE size: 45056 bytes
SVCHOST.EXE hash: E762F819A68A9FAA065A3965B37B664C

Created files:

%WinDir%\AppPatch\svchost.exe
%TEMP%\ddid
%Temp%\24C575.dmp
%Temp%\ddid

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\taskmgr\Type: 10010000
HKLM\System\CurrentControlSet\Services\taskmgr\Start: 02000000
HKLM\System\CurrentControlSet\Services\taskmgr\DisplayName: Mgr taks service
HKLM\System\CurrentControlSet\Services\taskmgr\ImagePath: %WinDir%\AppPatch\svchost.exe

Detected by UnHackMe:

SVCHOST.EXE
Default location: %WinDir%\APPPATCH\SVCHOST.EXE

Dropper information:
MD5: e762f819a68a9faa065a3965b37b664c
File size: 45056 bytes

Leave a Reply