Quantcast
Channel: How to Remove Malware
Viewing all articles
Browse latest Browse all 38585

SVCHQST.EXE is Trojan DNSChanger.ncl

$
0
0

We checked some samples of SVCHQST.EXE and detected the file SVCHQST.EXE as threat.
Remove the SVCHQST.EXE file from your computer right now.
Removal tool: http://www.unhackme.com

Malware Analysis of SVCHQST.EXE
Full path on a computer: %SysDir%\svchqst.exe

Detected by UnHackMe:

SVCHQST.EXE
Default location: %SysDir%\svchqst.exe

Removal Results: Success
Number of reboot: 1

SVCHQST.EXE is known as:

Trojan.DNSChanger.ncl, Trojan.Agent.Gen-Bifrose, TR.Rogue.8364302, Troj.AutoIt-OU, Backdoor.Bifrose.apwt, Troj.Scar.gv.(kcloud), Trojan.Dynamer.dtc, Trojan.A.Scar.334608, Trojan.Scar, W32.GenBl.8091E3AD.Olympus, Trojan.Autoit.F, Win32.Autoit.NLY, Trojan.Spy, W32.Scar.GVRZ.tr

SVCHQST.EXE hash:

  • MD5: 8091e3ad38e6515d045b336aa49bd18a
How to quickly detect SVCHQST.EXE presence?
Registry:
  • HKLM\System\CurrentControlSet\Services\WinDC\Type: 0×00000110
  • HKLM\System\CurrentControlSet\Services\WinDC\Start: 0×00000002
  • HKLM\System\CurrentControlSet\Services\WinDC\ErrorControl: 0×00000000
  • HKLM\System\CurrentControlSet\Services\WinDC\ImagePath: “”%SysDir%\svchqst.exe”"
  • HKLM\System\CurrentControlSet\Services\WinDC\DisplayName: “Windows DNS Client”
  • HKLM\System\CurrentControlSet\Services\WinDC\ObjectName: “LocalSystem”
Files:
  • %SysDir%\svchqst.exe
  • %SysDir%\svchqst.ini


Viewing all articles
Browse latest Browse all 38585

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>