I used VirusTotal to scan file SECOH-QAD.dll it out a notice dangerous this ???

Anonymous
2016-07-22T05:22:03+00:00

I used VirusTotal to scan file SECOH-QAD.dll it out a notice dangerous this ???

SHA256: 0398221231cff97e1fdc03d357ac4610afb8f3cdde4c90a9ec4d7823b405699e
Tên tập tin: SECOH-QAD.dll
Tỷ lệ phát hiện: 18 / 54
Ngày phân tích: 2016-07-22 05:07:40 UTC ( 2 phút trước )

43

47

AVware Trojan.Win32.Generic!BT 20160722
AegisLab Nettool.Win64.Rpchook!c 20160721
Antiy-AVL RiskWare[NetTool:not-a-virus]/Win64.RPCHook 20160722
CAT-QuickHeal NetTool.RPCHook.r4 (Not a Virus) 20160721
ESET-NOD32 Win64/HackKMS.D potentially unsafe 20160722
GData Win64.Application.Agent.YQQKJO 20160722
Ikarus PUA.NetTool.RPCHook 20160721
Jiangmin NetTool.RPCHook.k 20160722
K7AntiVirus Hacktool ( 000047b11 ) 20160721
K7GW Hacktool ( 000047b11 ) 20160722
Kaspersky not-a-virus:NetTool.Win64.RPCHook.a 20160722
McAfee Generic HTool.b 20160721
McAfee-GW-Edition Generic HTool.b 20160722
NANO-Antivirus Riskware.Win64.HackKMS.dzkjpw 20160722
VIPRE Trojan.Win32.Generic!BT 20160722
ViRobot RPCHook.3584[h] 20160722
Yandex Riskware.NetTool! 20160721
nProtect Trojan/W32.Agent.3584.MQ 20160721
ALYac 20160722
AVG 20160722
Ad-Aware 20160722
AhnLab-V3 20160721
Alibaba 20160722
Arcabit 20160722
Avast 20160722
Avira (no cloud) 20160721
Baidu 20160721
BitDefender 20160722
Bkav 20160721
CMC 20160715
ClamAV 20160722
Comodo 20160722
Cyren 20160722
DrWeb 20160722
Emsisoft 20160722
F-Prot 20160722
F-Secure 20160722
Fortinet 20160722
Kingsoft 20160722
Malwarebytes 20160722
eScan 20160722
Microsoft 20160722
Panda 20160721
Qihoo-360 20160722
SUPERAntiSpyware 20160722
Sophos 20160722
Symantec 20160722
Tencent 20160722
TheHacker 20160720
TrendMicro 20160722
TrendMicro-HouseCall 20160722
VBA32 20160721
Zillya 20160721
Zoner 20160722
Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

84 answers

Sort by: Newest
  1. Anonymous
    2016-08-19T09:40:33+00:00

    thank you

    Was this answer helpful?

    0 comments No comments
  2. Monkey57 3,535 Reputation points
    2016-08-19T09:03:58+00:00

    If you Win10 Reset (remove everything), you dont need to worry about removing anything beforehand, it will all be removed on reset.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2016-08-19T08:59:55+00:00

    I used Virustotal scan svchost.exe

    But nothing

    SHA256: 710134ffaf3a08d1b217da2f90afd85ae2e0d20f5d8968901b5943b26aa2f44b
    File name: svchost.exe
    Detection ratio: 0 / 55
    Analysis date: 2016-08-19 08:54:24 UTC ( 4 minutes ago )

    0

    1

    Probably harmless! There are strong indicators suggesting that this file is safe to use.

    ALYac 20160819
    AVG 20160819
    AVware 20160819
    Ad-Aware 20160819
    AegisLab 20160819
    AhnLab-V3 20160819
    Alibaba 20160819
    Antiy-AVL 20160819
    Arcabit 20160819
    Avast 20160819
    Avira (no cloud) 20160819
    Baidu 20160819
    BitDefender 20160819
    Bkav 20160818
    CAT-QuickHeal 20160818
    CMC 20160818
    ClamAV 20160819
    Comodo 20160818
    Cyren 20160819
    DrWeb 20160819
    ESET-NOD32 20160819
    Emsisoft 20160819
    F-Prot 20160819
    F-Secure 20160819
    Fortinet 20160819
    GData 20160819
    Ikarus 20160818
    Jiangmin 20160819
    K7AntiVirus 20160819
    K7GW 20160819
    Kaspersky 20160819
    Kingsoft 20160819
    Malwarebytes 20160819
    McAfee 20160819
    McAfee-GW-Edition 20160819
    eScan 20160819
    Microsoft 20160819
    NANO-Antivirus 20160819
    Panda 20160818
    Qihoo-360 20160819
    Rising 20160819
    SUPERAntiSpyware 20160819
    Sophos 20160819
    Symantec 20160819
    Tencent 20160819
    TheHacker 20160817
    TrendMicro 20160819
    TrendMicro-HouseCall 20160819
    VBA32 20160818
    VIPRE 20160819
    ViRobot 20160819
    Yandex 20160818
    Zillya 20160818
    Zoner 20160819
    nProtect 20160817

    Blog | Twitter | ******@virustotal.comGoogle groups | ToS | Privacy policy

    Was this answer helpful?

    0 comments No comments
  4. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  5. Anonymous
    2016-08-19T08:35:39+00:00

    Hello, sorry to bother you

    Today I opened PC up reinstalling Windows

    HitmanPro automatically scans and detects a file suspicious: svchotst.exe WRP 468 Serive

    svchost.exe what? delete it go yes affects system no?. I want to understand about it

    [code]

    HitmanPro 3.7.14.265

    www.hitmanpro.com

    Computer name . . . . : MAYTINH-1Q20GA5

       Windows . . . . . . . : 10.0.0.14393.X64/4

       User name . . . . . . : MAYTINH-1Q20GA5\MyPC

       UAC . . . . . . . . . : Enabled

       License . . . . . . . : Free

    Scan date . . . . . . : 2016-08-19 13:18:35

       Scan mode . . . . . . : Normal

       Scan duration . . . . : 7m 10s

       Disk access mode  . . : Direct disk access (SRB)

       Cloud . . . . . . . . : Internet

       Reboot  . . . . . . . : No

    Threats . . . . . . . : 0

       Traces  . . . . . . . : 219

    Objects scanned . . . : 1,714,816

       Files scanned . . . . : 26,345

       Remnants scanned  . . : 418,435 files / 1,270,036 keys

    Suspicious files ____________________________________________________________

    C:\WINDOWS\system32\svchost.exe

          Size . . . . . . . : 44,496 bytes

          Age  . . . . . . . : 12.3 days (2016-08-07 06:56:07)

          Entropy  . . . . . : 6.0

          SHA-256  . . . . . : 438B6CCD84F4DD32D9684ED7D58FD7D1E5A75FE3F3D12AB6C788E6BB0FFAD5E7

          Product  . . . . . : Microsoft® Windows® Operating System

          Publisher  . . . . : Microsoft Corporation

          Description  . . . : Host Process for Windows Services

          Version  . . . . . : 10.0.14393.0

          Copyright  . . . . : © Microsoft Corporation. All rights reserved.

          RSA Key Size . . . : 2048

          Service  . . . . . : WpnUserService_21d415d8

          Process Type . . . : Critical

          LanguageID . . . . : 1033

          Authenticode . . . : Valid

          Running processes  : 468, 488, 652, 868, 936, 972, 1076, 1512, 1704, 1748, 1828, 2208, 2224, 2232, 2848, 4352, 5476, 6412, 8640

          Fuzzy  . . . . . . : 23.0

             The file is completely hidden from view and most antivirus products. It may belong to a rootkit.

             This program is actively listening for inbound network connections.

             The file is in use by one or more active processes.

             The file is located in a folder that contains core operating system files from Windows. This is not typical for most programs and is only common to system tools, drivers and hacking utilities.

             Starts automatically as a service during system bootup.

             Time indicates that the file appeared recently on this computer.

             This file's process is marked as system critical.

             The file is protected by Windows File Protection (WFP). This is typical for critical Windows system files.

             Program is code signed with a valid Authenticode certificate.

          Startup

             HKLM\SYSTEM\ControlSet001\Services\CDPUserSvc_21d415d8\

             HKLM\SYSTEM\ControlSet001\Services\MessagingService_21d415d8\

             HKLM\SYSTEM\ControlSet001\Services\OneSyncSvc_21d415d8\

             HKLM\SYSTEM\ControlSet001\Services\PimIndexMaintenanceSvc_21d415d8\

             HKLM\SYSTEM\ControlSet001\Services\UnistoreSvc_21d415d8\

             HKLM\SYSTEM\ControlSet001\Services\UserDataSvc_21d415d8\

             HKLM\SYSTEM\ControlSet001\Services\WpnUserService_21d415d8\

             HKLM\SYSTEM\CurrentControlSet\Services\AJRouter\

             HKLM\SYSTEM\CurrentControlSet\Services\AppIDSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\Appinfo\

             HKLM\SYSTEM\CurrentControlSet\Services\AppMgmt\

             HKLM\SYSTEM\CurrentControlSet\Services\AppReadiness\

             HKLM\SYSTEM\CurrentControlSet\Services\AppXSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\AudioEndpointBuilder\

             HKLM\SYSTEM\CurrentControlSet\Services\Audiosrv\

             HKLM\SYSTEM\CurrentControlSet\Services\AxInstSV\

             HKLM\SYSTEM\CurrentControlSet\Services\BDESVC\

             HKLM\SYSTEM\CurrentControlSet\Services\BFE\

             HKLM\SYSTEM\CurrentControlSet\Services\BITS\

             HKLM\SYSTEM\CurrentControlSet\Services\BrokerInfrastructure\

             HKLM\SYSTEM\CurrentControlSet\Services\Browser\

             HKLM\SYSTEM\CurrentControlSet\Services\BthHFSrv\

             HKLM\SYSTEM\CurrentControlSet\Services\bthserv\

             HKLM\SYSTEM\CurrentControlSet\Services\CDPSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\CDPUserSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\CDPUserSvc_231c000e\

             HKLM\SYSTEM\CurrentControlSet\Services\CertPropSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\ClipSVC\

             HKLM\SYSTEM\CurrentControlSet\Services\CoreMessagingRegistrar\

             HKLM\SYSTEM\CurrentControlSet\Services\CryptSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\CscService\

             HKLM\SYSTEM\CurrentControlSet\Services\DcomLaunch\

             HKLM\SYSTEM\CurrentControlSet\Services\DcpSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\defragsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\DeviceAssociationService\

             HKLM\SYSTEM\CurrentControlSet\Services\DeviceInstall\

             HKLM\SYSTEM\CurrentControlSet\Services\DevQueryBroker\

             HKLM\SYSTEM\CurrentControlSet\Services\Dhcp\

             HKLM\SYSTEM\CurrentControlSet\Services\DiagTrack\

             HKLM\SYSTEM\CurrentControlSet\Services\DmEnrollmentSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\dmwappushservice\

             HKLM\SYSTEM\CurrentControlSet\Services\Dnscache\

             HKLM\SYSTEM\CurrentControlSet\Services\DoSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\dot3svc\

             HKLM\SYSTEM\CurrentControlSet\Services\DPS\

             HKLM\SYSTEM\CurrentControlSet\Services\DsmSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\DsSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\EapHost\

             HKLM\SYSTEM\CurrentControlSet\Services\embeddedmode\

             HKLM\SYSTEM\CurrentControlSet\Services\EntAppSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\EventLog\

             HKLM\SYSTEM\CurrentControlSet\Services\EventSystem\

             HKLM\SYSTEM\CurrentControlSet\Services\fdPHost\

             HKLM\SYSTEM\CurrentControlSet\Services\FDResPub\

             HKLM\SYSTEM\CurrentControlSet\Services\fhsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\FontCache\

             HKLM\SYSTEM\CurrentControlSet\Services\FrameServer\

             HKLM\SYSTEM\CurrentControlSet\Services\gpsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\hidserv\

             HKLM\SYSTEM\CurrentControlSet\Services\HomeGroupListener\

             HKLM\SYSTEM\CurrentControlSet\Services\HomeGroupProvider\

             HKLM\SYSTEM\CurrentControlSet\Services\HvHost\

             HKLM\SYSTEM\CurrentControlSet\Services\icssvc\

             HKLM\SYSTEM\CurrentControlSet\Services\IKEEXT\

             HKLM\SYSTEM\CurrentControlSet\Services\iphlpsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\irmon\

             HKLM\SYSTEM\CurrentControlSet\Services\KtmRm\

             HKLM\SYSTEM\CurrentControlSet\Services\LanmanServer\

             HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\

             HKLM\SYSTEM\CurrentControlSet\Services\lfsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\LicenseManager\

             HKLM\SYSTEM\CurrentControlSet\Services\lltdsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\lmhosts\

             HKLM\SYSTEM\CurrentControlSet\Services\LSM\

             HKLM\SYSTEM\CurrentControlSet\Services\MapsBroker\

             HKLM\SYSTEM\CurrentControlSet\Services\MessagingService\

             HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_231c000e\

             HKLM\SYSTEM\CurrentControlSet\Services\MpsSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\MSiSCSI\

             HKLM\SYSTEM\CurrentControlSet\Services\NcaSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\NcbService\

             HKLM\SYSTEM\CurrentControlSet\Services\NcdAutoSetup\

             HKLM\SYSTEM\CurrentControlSet\Services\Netman\

             HKLM\SYSTEM\CurrentControlSet\Services\netprofm\

             HKLM\SYSTEM\CurrentControlSet\Services\NetSetupSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\NgcCtnrSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\NgcSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\NlaSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\nsi\

             HKLM\SYSTEM\CurrentControlSet\Services\OneSyncSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\OneSyncSvc_231c000e\

             HKLM\SYSTEM\CurrentControlSet\Services\p2pimsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\p2psvc\

             HKLM\SYSTEM\CurrentControlSet\Services\PcaSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\PeerDistSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\PhoneSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc_231c000e\

             HKLM\SYSTEM\CurrentControlSet\Services\pla\

             HKLM\SYSTEM\CurrentControlSet\Services\PlugPlay\

             HKLM\SYSTEM\CurrentControlSet\Services\PNRPAutoReg\

             HKLM\SYSTEM\CurrentControlSet\Services\PNRPsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\PolicyAgent\

             HKLM\SYSTEM\CurrentControlSet\Services\Power\

             HKLM\SYSTEM\CurrentControlSet\Services\PrintNotify\

             HKLM\SYSTEM\CurrentControlSet\Services\ProfSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\QWAVE\

             HKLM\SYSTEM\CurrentControlSet\Services\RasAuto\

             HKLM\SYSTEM\CurrentControlSet\Services\RasMan\

             HKLM\SYSTEM\CurrentControlSet\Services\RemoteAccess\

             HKLM\SYSTEM\CurrentControlSet\Services\RemoteRegistry\

             HKLM\SYSTEM\CurrentControlSet\Services\RetailDemo\

             HKLM\SYSTEM\CurrentControlSet\Services\RmSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\RpcEptMapper\

             HKLM\SYSTEM\CurrentControlSet\Services\RpcSs\

             HKLM\SYSTEM\CurrentControlSet\Services\SCardSvr\

             HKLM\SYSTEM\CurrentControlSet\Services\ScDeviceEnum\

             HKLM\SYSTEM\CurrentControlSet\Services\Schedule\

             HKLM\SYSTEM\CurrentControlSet\Services\SCPolicySvc\

             HKLM\SYSTEM\CurrentControlSet\Services\SDRSVC\

             HKLM\SYSTEM\CurrentControlSet\Services\seclogon\

             HKLM\SYSTEM\CurrentControlSet\Services\SENS\

             HKLM\SYSTEM\CurrentControlSet\Services\SensorService\

             HKLM\SYSTEM\CurrentControlSet\Services\SensrSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\SessionEnv\

             HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\

             HKLM\SYSTEM\CurrentControlSet\Services\ShellHWDetection\

             HKLM\SYSTEM\CurrentControlSet\Services\shpamsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\smphost\

             HKLM\SYSTEM\CurrentControlSet\Services\SmsRouter\

             HKLM\SYSTEM\CurrentControlSet\Services\SSDPSRV\

             HKLM\SYSTEM\CurrentControlSet\Services\SstpSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\StateRepository\

             HKLM\SYSTEM\CurrentControlSet\Services\stisvc\

             HKLM\SYSTEM\CurrentControlSet\Services\StorSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\svsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\swprv\

             HKLM\SYSTEM\CurrentControlSet\Services\SysMain\

             HKLM\SYSTEM\CurrentControlSet\Services\SystemEventsBroker\

             HKLM\SYSTEM\CurrentControlSet\Services\TabletInputService\

             HKLM\SYSTEM\CurrentControlSet\Services\TapiSrv\

             HKLM\SYSTEM\CurrentControlSet\Services\TermService\

             HKLM\SYSTEM\CurrentControlSet\Services\Themes\

             HKLM\SYSTEM\CurrentControlSet\Services\tiledatamodelsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\TimeBrokerSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\TrkWks\

             HKLM\SYSTEM\CurrentControlSet\Services\tzautoupdate\

             HKLM\SYSTEM\CurrentControlSet\Services\UmRdpService\

             HKLM\SYSTEM\CurrentControlSet\Services\UnistoreSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\UnistoreSvc_231c000e\

             HKLM\SYSTEM\CurrentControlSet\Services\upnphost\

             HKLM\SYSTEM\CurrentControlSet\Services\UserDataSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\UserDataSvc_231c000e\

             HKLM\SYSTEM\CurrentControlSet\Services\UserManager\

             HKLM\SYSTEM\CurrentControlSet\Services\UsoSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\vmicguestinterface\

             HKLM\SYSTEM\CurrentControlSet\Services\vmicheartbeat\

             HKLM\SYSTEM\CurrentControlSet\Services\vmickvpexchange\

             HKLM\SYSTEM\CurrentControlSet\Services\vmicrdv\

             HKLM\SYSTEM\CurrentControlSet\Services\vmicshutdown\

             HKLM\SYSTEM\CurrentControlSet\Services\vmictimesync\

             HKLM\SYSTEM\CurrentControlSet\Services\vmicvmsession\

             HKLM\SYSTEM\CurrentControlSet\Services\vmicvss\

             HKLM\SYSTEM\CurrentControlSet\Services\W32Time\

             HKLM\SYSTEM\CurrentControlSet\Services\WalletService\

             HKLM\SYSTEM\CurrentControlSet\Services\WbioSrvc\

             HKLM\SYSTEM\CurrentControlSet\Services\Wcmsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\wcncsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\WdiServiceHost\

             HKLM\SYSTEM\CurrentControlSet\Services\WdiSystemHost\

             HKLM\SYSTEM\CurrentControlSet\Services\WebClient\

             HKLM\SYSTEM\CurrentControlSet\Services\Wecsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\WEPHOSTSVC\

             HKLM\SYSTEM\CurrentControlSet\Services\wercplsupport\

             HKLM\SYSTEM\CurrentControlSet\Services\WerSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\WiaRpc\

             HKLM\SYSTEM\CurrentControlSet\Services\WinHttpAutoProxySvc\

             HKLM\SYSTEM\CurrentControlSet\Services\Winmgmt\

             HKLM\SYSTEM\CurrentControlSet\Services\WinRM\

             HKLM\SYSTEM\CurrentControlSet\Services\wisvc\

             HKLM\SYSTEM\CurrentControlSet\Services\WlanSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\wlidsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\workfolderssvc\

             HKLM\SYSTEM\CurrentControlSet\Services\WPDBusEnum\

             HKLM\SYSTEM\CurrentControlSet\Services\WpnService\

             HKLM\SYSTEM\CurrentControlSet\Services\WpnUserService\

             HKLM\SYSTEM\CurrentControlSet\Services\WpnUserService_231c000e\

             HKLM\SYSTEM\CurrentControlSet\Services\wscsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\wuauserv\

             HKLM\SYSTEM\CurrentControlSet\Services\wudfsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\WwanSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\XblAuthManager\

             HKLM\SYSTEM\CurrentControlSet\Services\XblGameSave\

             HKLM\SYSTEM\CurrentControlSet\Services\XboxNetApiSvc\

          Network Ports

             0.0.0.0:135 

             0.0.0.0:1537 

             0.0.0.0:1538 

             192.168.1.79:8905 111.221.29.107:443

             192.168.1.79:8970 2.17.48.130:80

    [/code]

    Was this answer helpful?

    0 comments No comments