PCHSVC.DLL - Dangerous
%SysDir%\PCHSVC.DLL
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
PCHSVC.DLL is known as: Exploit:Win32/ShellCode.gen!B [Microsoft] packed with ASPack [Kaspersky Lab].
MD5 of PCHSVC.DLL = F7260BF6AEF47E258DF88F2A8715C359
PCHSVC.DLL size is 227840 bytes.
Full path on a computer: %SYSTEM%\PCHSVC.DLL
Related Files:
C:\1.EXE
%COMMONAPPDATA%\MICROSOFT\NETWORK\DOWNLOADER\QMGR1.DAT
%PROFILES%\LOCALSERVICE\APPLICATION DATA\MICROSOFT\UPNP DEVICE HOST\UPNPHOST\UDHISAPI.DLL
%PROFILES%\NETWORKSERVICE\FAVORITES\DESKTOP.INI
%SYSTEM%\WINNT.COM
%SYSTEM%\DBR99005.OCX
%TEMP%\73222A01.LOG
%TEMP%\E_4\KRNLN.FNR
%FONTSDIR%\DBR03017.TTF
%FONTSDIR%\DBR06030.TTF
%FONTSDIR%\DBR09021.TTF
%FONTSDIR%\DBR11022.TTF
%SYSTEM%\60520064.SYS
%SYSTEM%\PCHSVC.DLL
%SYSTEM%\COMRES.DLL.BAK
%SYSTEM%\C_20167.NLS
%SYSTEM%\DBR03017.OCX
%SYSTEM%\DBR06030.OCX
%SYSTEM%\DBR09021.OCX
%SYSTEM%\DDRAW.DLL.BAK
%SYSTEM%\DMLOCALSVC.DLL
%SYSTEM%\DSOUND.DLL.BAK
%SYSTEM%\GBVGBV09.EXE
%WINDIR%\TEMP\27CA0B06.RAR
%WINDIR%\TEMP\45305014.EXE
%WINDIR%\TEMP\54C53E81.RAR