svchost..exe

WindowsFormsApplication5

The executable svchost..exe, “Host Process for Windows Services” has been detected as malware by 38 anti-virus scanners.
Publisher:
Microsoft*  (Invalid match)

Product:
WindowsFormsApplication5

Description:
Host Process for Windows Services

Version:
1.0.0.0

MD5:
c2aa17ba08c6bfb252adf8d2b9295e6a

SHA-1:
bccf20c51a32a341188b9d5c958ba27cf91c4cdc

SHA-256:
ecef732fb83742e144640658f9e7c9267f7296f3de3e925e9d7e0a52f8a91dcc

Scanner detections:
38 / 68

Status:
Malware

Analysis date:
4/25/2024 1:55:50 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.KDV.514407
-40

Agnitum Outpost
Worm.Agent
7.1.1

AhnLab V3 Security
Worm/Win32.Agent
2014.08.14

Avira AntiVirus
Worm/Mofin.A.1
7.11.167.34

avast!
MSIL:Agent-ABU [Trj]
2014.9-170316

Baidu Antivirus
Trojan.MSIL.Agent
4.0.3.17316

Bitdefender
Trojan.Generic.KDV.514407
1.0.20.375

Bkav FE
W32.VertonkitLTAAAAG.Trojan
1.3.0.4959

Clam AntiVirus
Win.Worm.Agent-718
0.98/21411

Comodo Security
Worm.MSIL.Agent.AY
19186

Dr.Web
Trojan.Siggen3.38290
9.0.1.075

Emsisoft Anti-Malware
Trojan.Generic.KDV.514407
8.17.03.16.04

ESET NOD32
MSIL/Agent.AY
11.10253

Fortinet FortiGate
MSIL/Agent.QBS!tr
3/16/2017

F-Prot
W32/MSIL_Agent.K.gen
v6.4.7.1.166

F-Secure
Trojan.Generic.KDV.514407
11.2017-16-03_5

G Data
Trojan.Generic.KDV.514407
17.3.24

IKARUS anti.virus
Worm.Win32.Msil
t3scan.1.7.5.0

K7 AntiVirus
NetWorm
13.183.13043

Kaspersky
Trojan.MSIL.Agent
14.0.0.-1316

Malwarebytes
Trojan.MSIL
v2017.03.16.04

McAfee
Generic Malware.og!ats
5600.6094

Microsoft Security Essentials
Worm:MSIL/Mofin.A
1.10802

MicroWorld eScan
Trojan.Generic.KDV.514407
18.0.0.225

NANO AntiVirus
Trojan.Win32.Agent.cqkyab
0.28.2.61519

Norman
Agent.AKXUE
11.20170316

nProtect
Trojan/W32.Agent.114688.CPS
14.08.13.01

Panda Antivirus
Generic Malware
17.03.16.04

Qihoo 360 Security
Malware.QVM03.Gen
1.0.0.1015

Quick Heal
Worm.Necast.A3
3.17.14.00

Rising Antivirus
PE:Trojan.FakeFolder@CV!1.6ABA
23.00.65.17314

Sophos
Mal/MSIL-EY
4.98

SUPERAntiSpyware
Worm.Necast
8533

Total Defense
Win32/Tnega.ASFT
37.0.11118

Trend Micro House Call
TROJ_SPNR.06AN12
7.2.75

Trend Micro
TROJ_SPNR.06AN12
10.465.16

Vba32 AntiVirus
Trojan.MSIL.Agent.dkwx
3.12.26.3

VIPRE Antivirus
Worm.MSIL.Mofin.a
32204

File size:
112 KB (114,688 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2011

Original file name:
WindowsFormsApplication5.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\roaming\microsoft\windows\start menu\programs\startup\svchost..exe

File PE Metadata
Compilation timestamp:
2/27/2002 8:03:56 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

Entry address:
0x5E1E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.2640

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
16 KB (16,384 bytes)

User Start Menu Item
Name:
svchost..exe


Remove svchost..exe - Powered by Reason Core Security