SCVHOSTS.EXE – Virus Sality

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

SCVHOSTS.EXE – Virus Sality removal

FileMD5Virus Alias
SCVHOSTS.EXE 28f7694ff86ade89881ee0b7f503283a Virus Sality
SCVHOSTS.EXE 28f7694ff86ade89881ee0b7f503283a Trojan Hllw
SCVHOSTS.EXE 28f7694ff86ade89881ee0b7f503283a Trojan Downloader
SCVHOSTS.EXE 28f7694ff86ade89881ee0b7f503283a Worm Autoit
SCVHOSTS.EXE 28f7694ff86ade89881ee0b7f503283a Worm Autorun
SCVHOSTS.EXE 28f7694ff86ade89881ee0b7f503283a Trojan Agent

SCVHOSTS.EXE size: 295849 bytes
SCVHOSTS.EXE hash: 28F7694FF86ADE89881EE0B7F503283A

Created files:

C:\3947db
%WinDir%\hinhem.scr
%WinDir%\scvhosts.exe
%SysDir%\blastclnnn.exe
%SysDir%\scvhosts.exe
%TEMP%\00394027_Rar\28F7694FF86ADE89881EE0B7F503283A.EXE
D:\394b89
D:\cert\VBoxCertUtil.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: Explorer.exe scvhosts.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Yahoo Messengger: %WinDir%\System32\scvhosts.exe

Detected by UnHackMe:

SCVHOSTS.EXE
Default location: %WinDir%\SCVHOSTS.EXE

Dropper information:
MD5: 28f7694ff86ade89881ee0b7f503283a
File size: 295849 bytes

Leave a Reply