The file SVCHOST.EXE.EXE can destroy your system, thus making the computer to work abnormally.
SVCHOST.EXE.EXE is a dangerous file.
RemoveSVCHOST.EXE.EXE from your computer immediately.
Kill the process SVCHOST.EXE.EXE and remove SVCHOST.EXE.EXE from the Windows startup.
Malware Analysis of C:\M7ZTT4HC7QBV
Full path on a computer: C:\M7ZTT4HC7QBV
Detected by RegRun Warrior:
Item Name: SysUpdate
Author:
Current Setting: C:\M7ztT4Hc7qBv\Windows Update/
Type: Registry Run
Item Name: UserInit
Author: Unknown
Related File: %SysDir%\userinit.exe,C:\M7ztT4Hc7qBv\Windows Update/,C:\M7ztT4Hc7qBv\Windows Update/
Type: UserInit Value
Item Name: UserInit
Author: Unknown
Related File: %SysDir%\userinit.exe,C:\M7ztT4Hc7qBv\Windows Update/,C:\M7ztT4Hc7qBv\Windows Update/
Type: UserInit Value
Removal Results: Success
Number of reboot: 1
C:\M7ZTT4HC7QBV is known as:
Trojan.Comet, Darkkomet.M, a variant of MSIL.Kryptik.PX, Backdoor.DarkKomet.bsnu, Trojan.Kazy.dQdfB4TdbAY, BackDoor.Comet.152, TR.Dropper.MSIL.18156, Backdoor.DarkKomet, MSIL.Kryptik.PX.tr, MSIL.CFXH, Backdoor.DarkKomet.aY
SVCHOST.EXE.EXE hash:
- MD5: ac72d089724e6018f9a0c4e530e497a0
- HKCU\Software\Microsoft\Windows\CurrentVersion\Run\SwiftKit: “%Temp%\svchost.exe.exe”
- HKCU\Software\Microsoft\Windows\CurrentVersion\Run\SysUpdate: “C:\M7ztT4Hc7qBv\Windows Update/”
- HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit: “%SysDir%\userinit.exe,C:\M7ztT4Hc7qBv\Windows Update/”
- C:\M7ztT4Hc7qBv
- %Temp%\svchost.exe.exe