SVSCHOST.EXE – Trojan Generic

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

SVSCHOST.EXE – Trojan Generic removal

FileMD5Virus Alias
SVSCHOST.EXE ff21d86bcb6e63a4d0099633a927ef48 Trojan Generic

SVSCHOST.EXE size: 11264 bytes
SVSCHOST.EXE hash: FF21D86BCB6E63A4D0099633A927EF48

Created files:

C:\ProgramData\stppthmain\stppthmain.dll
%SysDir%\cfwin32.dll
%SysDir%\csrss32.dll
%SysDir%\csrss64.dll
%SysDir%\default2.sfx
%SysDir%\NoSafeMode.dll
%SysDir%\nsf.exe
%SysDir%\sdelete.dll
%SysDir%\svchostsv.exe
%SysDir%\svschost.exe

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\fdPHosts\Type: 10000000
HKLM\System\CurrentControlSet\Services\fdPHosts\Start: 02000000
HKLM\System\CurrentControlSet\Services\fdPHosts\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\fdPHosts\DisplayName: Wdi Function Discovery Provider Host Records
HKLM\System\CurrentControlSet\Services\fdPHosts\ImagePath: %WinDir%\System32\svschost.exe
HKLM\System\CurrentControlSet\Services\NIaSvc\Type: 10000000
HKLM\System\CurrentControlSet\Services\NIaSvc\Start: 02000000
HKLM\System\CurrentControlSet\Services\NIaSvc\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\NIaSvc\DisplayName: Network Locatlon Awareness
HKLM\System\CurrentControlSet\Services\NIaSvc\ImagePath: %WinDir%\System32\svchostsv.exe

Detected by UnHackMe:

SVSCHOST.EXE
Default location: %SYSDIR%\SVSCHOST.EXE

Dropper information:
MD5: 457add522ab4f68e334534720ab777cd
File size: 586042 bytes

Leave a Reply