svchost.exe

Host Process for Windows Services

ABDULKADIR SAHIN

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The application svchost.exe, “Host Process for Windows Services” by ABDULKADIR SAHIN has been detected as adware by 6 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “svchost”. Although this file uses the name svchost.exe, this is NOT the Windows SvcHost (Service Host) distributed with the OS.
Publisher:
Microsoft Corporation  (signed by ABDULKADIR SAHIN)

Product:
Microsoft® Windows® Operating System

Description:
Host Process for Windows Services

Version:
6.1.7600.16385

MD5:
a51cc4e0aba1ce911fcee79e2828955a

SHA-1:
c195c4da610df5263187291425ac449e99412f50

SHA-256:
bb01e1d3ae4261edcb82c18a15e6538edb5dc4bfd210da11b80f9c330890f7f9

Scanner detections:
6 / 68

Status:
Adware

Analysis date:
4/26/2024 7:01:22 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Trojan/Win32.Agent
2013.12.29

AVG
Luhe.MSIL.D
2015.0.3596

Malwarebytes
Trojan.MSIL.FakeMS
v2014.01.12.01

Reason Heuristics
PUP.Service.ABDULKADIRSAHIN.H
14.7.3.9

Trend Micro House Call
TROJ_GEN.F47V1219
7.2.12

XVirus List
Win32.Detected
2.7.3

File size:
26.3 KB (26,960 bytes)

Product version:
6.1.7600.16385

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
svchost.exe

File type:
Executable application (Win32 EXE)

Language:
Turkish (Turkey)

Common path:
C:\ProgramData\svchost.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/18/2013 2:00:00 AM

Valid to:
3/20/2014 1:59:59 AM

Subject:
CN=ABDULKADIR SAHIN, OU=Individual Developer, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=No Organization Affiliation, L=ANKARA, S=KECIOREN, C=TR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
516CAE126302D8B129C8550A077CDF6F

File PE Metadata
Compilation timestamp:
12/20/2013 3:16:42 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
384:Vwgxi3Z3GyGrTBYvP96uHXSvP19g96ul2T1px7W9xdWenYPLEKBZ7deMOO:VwoyMy4Bm2TCP9YIO

Entry address:
0x61DE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 7B, 05, 4A, 0C, F4, 9C, DD, 9A, 79, DD, B7, 29, 79, 41, 09, 2B, 43, 51, 17, 2B, 4A, 3F, 40, 17, 5F, B9, E2, F4, 2D, C2, D3, 2B, 75, FE, 29, 79, 41, 34, 09, 2B, DD, 9A, 0C, 36, 44, F1, 44, 42, 52, 66, 68, 6E, 20, 4D, 18, 22, 76, B5, 33, 11, 12, 33, 0C, 6D, 0A, 20, 4D, 18, 22, 9E, A1, 29, 61, 1C, 76, B5, 05, 19, 01, 58, 04, 00, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
16.5 KB (16,896 bytes)

Service
Display name:
svchost

Type:
Win32OwnProcess


Remove svchost.exe - Powered by Reason Core Security