svchost.exe

The executable svchost.exe has been detected as malware by 4 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘wjmJfWtbcToQr’. Although this file uses the name svchost.exe, this is NOT the Windows SvcHost (Service Host) distributed with the OS.
MD5:
969cd9f4e82ab1561c3b74549a025373

SHA-1:
77c3b3c12f2b04e888031a0c46daf5d1f7e1dc19

SHA-256:
e2bc31b6280cfa8a32b244eb90a0e983680da664b8eee19bf2842aa514657b75

Scanner detections:
4 / 68

Status:
Malware

Analysis date:
4/1/2025 8:16:18 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Malware-gen
160917-0

Clam AntiVirus
Win.Trojan.Agent-1331021
0.98/23207

Dr.Web
Trojan.DownLoad3.32925
9.0.1.05190

F-Prot
W32/Threat-HLLIE-based
4.6.5.141

File size:
712 KB (729,088 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\windows\svchost.exe

File PE Metadata
Compilation timestamp:
6/20/1992 7:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x41CBE4

Entry point:
60, E8, 00, 00, 00, 00, 5D, 81, ED, 06, 00, 00, 00, 81, ED, E4, CB, 41, 00, E9, 4C, 00, 00, 00, 45, 4E, 49, 47, 4D, 41, 03, 46, DE, 07, 08, 00, 1A, 00, 0E, 00, 27, 00, 24, 00, 42, 1D, E0, AC, 49, 1F, FC, 01, 0A, F5, 6A, B0, 97, 6A, 31, A5, 3A, 62, 93, EC, 01, 00, 00, 00, 4F, 1A, 33, 7A, 9B, 1F, C2, C9, 21, D1, 48, 53, 32, 7B, 5C, 8A, 4F, 1A, 33, 7A, 9B, 1F, C2, C9, 21, D1, 48, 53, 32, 7B, 5C, 8A, E9, 04, 00, 00, 00, CE, 54, 30, 4B, B8, E4, CB, 41, 00, 03, C5, 81, C0, 93, 00, 00, 00, B9, 87, 05, 00, 00, BA...
 
[+]

Entropy:
7.9766

Packer / compiler:
ASPack v1.08.04

Code size:
25 KB (25,600 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
wjmJfWtbcToQr

Command:
"C:\users\{user}\appdata\local\svchost.exe"


Remove svchost.exe - Powered by Reason Core Security