SCVVHSOT.EXE – Virus Sality

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

SCVVHSOT.EXE – Virus Sality removal

FileMD5Virus Alias
SCVVHSOT.EXE 2edb218d169029eb8ed0382e390268e4 Virus Sality
SCVVHSOT.EXE 2edb218d169029eb8ed0382e390268e4 Worm Autoit
SCVVHSOT.EXE 2edb218d169029eb8ed0382e390268e4 Trojan Agent

SCVVHSOT.EXE size: 369152 bytes
SCVVHSOT.EXE hash: 2EDB218D169029EB8ED0382E390268E4

Created files:

C:\15463ac
%WinDir%\SCVVHSOT.exe
%SysDir%\blastclnnn.exe
%SysDir%\SCVVHSOT.exe
%TEMP%\015461CC_Rar\2EDB218D169029EB8ED0382E390268E4.EXE
%TEMP%\winvenk.exe
D:\15467a0
D:\cert\VBoxCertUtil.exe
D:\OS2\VBoxControl.exe
D:\OS2\VBoxService.exe
D:\VBoxWindowsAdditions-amd64.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: Explorer.exe SCVVHSOT.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Yahoo Messengger: %WinDir%\System32\SCVVHSOT.exe

Detected by UnHackMe:

SCVVHSOT.EXE
Default location: %WinDir%\SCVVHSOT.EXE

Dropper information:
MD5: 2edb218d169029eb8ed0382e390268e4
File size: 369152 bytes

Leave a Reply