| syshost.exe | |
| PE32 executable (GUI) Intel 80386, for MS Windows | 131072 bytes |
| 2016-08-10 20:04:18 | |
| 8b0cca757e097e452182a8e6c2090e13 | |
| d8ce82e98368c92a9a43d0fed36b3fa012799800 | |
| d138afbd6ed696ed5489136123621fb04c0592a2b4d288e3dadd6d6d93693baa | |
| 2a5d82489eeb5ce3fc437925c5d7fae805ef236da4c95315f0d2275cf3645d10c6a0f6edb1f8fefb7c0c5b0feb81967964a81798426e7b38cfc6454c9dbd2c69 | |
| 3072:2IkiQxhb8q31FVJ+A8Htp4VZIBc6BF0DrEoq0HbpucNVZQy+:DtQ331V+A87ISBct3EoqOgc | |
| 08e0058cbd37acdc1570c59f130ad30d | |
| N/A | |

| AVG | Generic_r.LYP |
| Ad-Aware | Trojan.GenericKD.3442089 |
| AhnLab-V3 | Dropper/Win32.Necurs.N2071109933 |
| Arcabit | Trojan.Generic.D3485A9 |
| Avast | Win32:Dropper-gen [Drp] |
| Avira | TR/Necurs.EL.1 |
| BitDefender | Trojan.GenericKD.3442089 |
| DrWeb | Trojan.Necurs.414 |
| ESET-NOD32 | Win32/TrojanDownloader.Necurs.B |
| Emsisoft | Trojan.GenericKD.3442089 (B) |
| F-Secure | Trojan.GenericKD.3442089 |
| GData | Trojan.GenericKD.3442089 |
| Ikarus | Trojan-Downloader.Win32.Necurs |
| K7AntiVirus | Trojan-Downloader ( 004b96921 ) |
| K7GW | Trojan-Downloader ( 004b96921 ) |
| Kaspersky | Trojan-Dropper.Win32.Necurs.aaim |
| Malwarebytes | Trojan.MalPack |
| McAfee | Artemis!8B0CCA757E09 |
| McAfee-GW-Edition | BehavesLike.Win32.VBObfus.ch |
| MicroWorld-eScan | Trojan.GenericKD.3442089 |
| Microsoft | Trojan:Win32/Necurs |
| Panda | Trj/Necurs.G |
| Qihoo-360 | HEUR/QVM07.1.EA7A.Malware.Gen |
| Symantec | Heur.AdvML.B |
| Tencent | Win32.Trojan-dropper.Necurs.Dzts |
| TrendMicro | TROJ_DYER.BMC |
| TrendMicro-HouseCall | TROJ_DYER.BMC |
| HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
| HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders |
| HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System |
| HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor |
| HKEY_CURRENT_USER\Software\Microsoft\Command Processor |
| HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale |
| HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts |
| HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups |