Filename:
SVICHOOST.exe

Related to:
W32.Imaut.BH

File Directory:
%System%\
%Windir%\

Startup Type:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\”Shell” = “Explorer.exe SVICHOOST.exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\”Yahoo Messengger” = “%System%\SVICHOOST.exe”

Removal and Protection:
Deleting the file SVICHOOST.exe will not help in removing the threat on computer. Antivirus and Anti-Spyware Software are recommended for automatic removal and protection.