Solved! Use DLLHOST.COM (Worm Autorun) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

DLLHOST.COM – Worm Autorun removal

File MD5 Virus Alias
DLLHOST.COM 9619d9f104a05e8bc855da3eff07ab02 Worm Autorun
DLLHOST.COM 9619d9f104a05e8bc855da3eff07ab02 Trojan, Suspicious File
DLLHOST.COM 9619d9f104a05e8bc855da3eff07ab02 Trojan Artemis
DLLHOST.COM 9619d9f104a05e8bc855da3eff07ab02 Trojan Eldorado
DLLHOST.COM 9619d9f104a05e8bc855da3eff07ab02 Trojan Siggen
DLLHOST.COM 9619d9f104a05e8bc855da3eff07ab02 Trojan Agent

DLLHOST.COM size: 79790 bytes
DLLHOST.COM hash: 9619D9F104A05E8BC855DA3EFF07AB02

Created files:

C:\Documents and Settings\Default User\My Documents\My Videos
C:\Documents and Settings\Default User\Start Menu\Programs\Startup\ .exe
%WinDir%\system\dllhost.com
%SysDir%\SVCH0ST.EXE
%Common Startmenu%\Programs\Startup\ .exe
%AppData%\Microsoft\Internet Explorer\Quick Launch\TEST.exe
%Favorites%\Links\www.test.com
%Temp%\TEST.EXE
%Personal%\My Music\Private Letters.exe
%Startup%\ .exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\run\Microsoft Agent: %WinDir%\System32\SVCH0ST.EXE
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\shell: Explorer.exe %WinDir%/System32/SVCH0ST.EXE
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\load: %WinDir%/System/dllhost.com

Detected by UnHackMe:

DLLHOST.COM
Default location: %WinDir%\SYSTEM\DLLHOST.COM

Dropper information:
MD5: 9619d9f104a05e8bc855da3eff07ab02
File size: 79790 bytes

Leave a Reply