thank you
I used VirusTotal to scan file SECOH-QAD.dll it out a notice dangerous this ???
I used VirusTotal to scan file SECOH-QAD.dll it out a notice dangerous this ???
| SHA256: | 0398221231cff97e1fdc03d357ac4610afb8f3cdde4c90a9ec4d7823b405699e |
|---|---|
| Tên tập tin: | SECOH-QAD.dll |
| Tỷ lệ phát hiện: | 18 / 54 |
| Ngày phân tích: | 2016-07-22 05:07:40 UTC ( 2 phút trước ) |
43
47
| AVware | Trojan.Win32.Generic!BT | 20160722 |
|---|---|---|
| AegisLab | Nettool.Win64.Rpchook!c | 20160721 |
| Antiy-AVL | RiskWare[NetTool:not-a-virus]/Win64.RPCHook | 20160722 |
| CAT-QuickHeal | NetTool.RPCHook.r4 (Not a Virus) | 20160721 |
| ESET-NOD32 | Win64/HackKMS.D potentially unsafe | 20160722 |
| GData | Win64.Application.Agent.YQQKJO | 20160722 |
| Ikarus | PUA.NetTool.RPCHook | 20160721 |
| Jiangmin | NetTool.RPCHook.k | 20160722 |
| K7AntiVirus | Hacktool ( 000047b11 ) | 20160721 |
| K7GW | Hacktool ( 000047b11 ) | 20160722 |
| Kaspersky | not-a-virus:NetTool.Win64.RPCHook.a | 20160722 |
| McAfee | Generic HTool.b | 20160721 |
| McAfee-GW-Edition | Generic HTool.b | 20160722 |
| NANO-Antivirus | Riskware.Win64.HackKMS.dzkjpw | 20160722 |
| VIPRE | Trojan.Win32.Generic!BT | 20160722 |
| ViRobot | RPCHook.3584[h] | 20160722 |
| Yandex | Riskware.NetTool! | 20160721 |
| nProtect | Trojan/W32.Agent.3584.MQ | 20160721 |
| ALYac | 20160722 | |
| AVG | 20160722 | |
| Ad-Aware | 20160722 | |
| AhnLab-V3 | 20160721 | |
| Alibaba | 20160722 | |
| Arcabit | 20160722 | |
| Avast | 20160722 | |
| Avira (no cloud) | 20160721 | |
| Baidu | 20160721 | |
| BitDefender | 20160722 | |
| Bkav | 20160721 | |
| CMC | 20160715 | |
| ClamAV | 20160722 | |
| Comodo | 20160722 | |
| Cyren | 20160722 | |
| DrWeb | 20160722 | |
| Emsisoft | 20160722 | |
| F-Prot | 20160722 | |
| F-Secure | 20160722 | |
| Fortinet | 20160722 | |
| Kingsoft | 20160722 | |
| Malwarebytes | 20160722 | |
| eScan | 20160722 | |
| Microsoft | 20160722 | |
| Panda | 20160721 | |
| Qihoo-360 | 20160722 | |
| SUPERAntiSpyware | 20160722 | |
| Sophos | 20160722 | |
| Symantec | 20160722 | |
| Tencent | 20160722 | |
| TheHacker | 20160720 | |
| TrendMicro | 20160722 | |
| TrendMicro-HouseCall | 20160722 | |
| VBA32 | 20160721 | |
| Zillya | 20160721 | |
| Zoner | 20160722 |
Windows for home | Windows 10 | Security and privacy
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
84 answers
Sort by: Newest
-
Anonymous
2016-08-19T09:40:33+00:00 -
Monkey57 3,535 Reputation points
2016-08-19T09:03:58+00:00 If you Win10 Reset (remove everything), you dont need to worry about removing anything beforehand, it will all be removed on reset.
-
Anonymous
2016-08-19T08:59:55+00:00 I used Virustotal scan svchost.exe
But nothing
SHA256: 710134ffaf3a08d1b217da2f90afd85ae2e0d20f5d8968901b5943b26aa2f44b File name: svchost.exe Detection ratio: 0 / 55 Analysis date: 2016-08-19 08:54:24 UTC ( 4 minutes ago ) 0
1
Probably harmless! There are strong indicators suggesting that this file is safe to use.
ALYac 20160819 AVG 20160819 AVware 20160819 Ad-Aware 20160819 AegisLab 20160819 AhnLab-V3 20160819 Alibaba 20160819 Antiy-AVL 20160819 Arcabit 20160819 Avast 20160819 Avira (no cloud) 20160819 Baidu 20160819 BitDefender 20160819 Bkav 20160818 CAT-QuickHeal 20160818 CMC 20160818 ClamAV 20160819 Comodo 20160818 Cyren 20160819 DrWeb 20160819 ESET-NOD32 20160819 Emsisoft 20160819 F-Prot 20160819 F-Secure 20160819 Fortinet 20160819 GData 20160819 Ikarus 20160818 Jiangmin 20160819 K7AntiVirus 20160819 K7GW 20160819 Kaspersky 20160819 Kingsoft 20160819 Malwarebytes 20160819 McAfee 20160819 McAfee-GW-Edition 20160819 eScan 20160819 Microsoft 20160819 NANO-Antivirus 20160819 Panda 20160818 Qihoo-360 20160819 Rising 20160819 SUPERAntiSpyware 20160819 Sophos 20160819 Symantec 20160819 Tencent 20160819 TheHacker 20160817 TrendMicro 20160819 TrendMicro-HouseCall 20160819 VBA32 20160818 VIPRE 20160819 ViRobot 20160819 Yandex 20160818 Zillya 20160818 Zoner 20160819 nProtect 20160817 Blog | Twitter | ******@virustotal.com| Google groups | ToS | Privacy policy
-
Deleted
This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.
Comments have been turned off. Learn more
-
Anonymous
2016-08-19T08:35:39+00:00 Hello, sorry to bother you
Today I opened PC up reinstalling Windows
HitmanPro automatically scans and detects a file suspicious: svchotst.exe WRP 468 Serive
svchost.exe what? delete it go yes affects system no?. I want to understand about it
[code]
HitmanPro 3.7.14.265
Computer name . . . . : MAYTINH-1Q20GA5
Windows . . . . . . . : 10.0.0.14393.X64/4
User name . . . . . . : MAYTINH-1Q20GA5\MyPC
UAC . . . . . . . . . : Enabled
License . . . . . . . : Free
Scan date . . . . . . : 2016-08-19 13:18:35
Scan mode . . . . . . : Normal
Scan duration . . . . : 7m 10s
Disk access mode . . : Direct disk access (SRB)
Cloud . . . . . . . . : Internet
Reboot . . . . . . . : No
Threats . . . . . . . : 0
Traces . . . . . . . : 219
Objects scanned . . . : 1,714,816
Files scanned . . . . : 26,345
Remnants scanned . . : 418,435 files / 1,270,036 keys
Suspicious files ____________________________________________________________
C:\WINDOWS\system32\svchost.exe
Size . . . . . . . : 44,496 bytes
Age . . . . . . . : 12.3 days (2016-08-07 06:56:07)
Entropy . . . . . : 6.0
SHA-256 . . . . . : 438B6CCD84F4DD32D9684ED7D58FD7D1E5A75FE3F3D12AB6C788E6BB0FFAD5E7
Product . . . . . : Microsoft® Windows® Operating System
Publisher . . . . : Microsoft Corporation
Description . . . : Host Process for Windows Services
Version . . . . . : 10.0.14393.0
Copyright . . . . : © Microsoft Corporation. All rights reserved.
RSA Key Size . . . : 2048
Service . . . . . : WpnUserService_21d415d8
Process Type . . . : Critical
LanguageID . . . . : 1033
Authenticode . . . : Valid
Running processes : 468, 488, 652, 868, 936, 972, 1076, 1512, 1704, 1748, 1828, 2208, 2224, 2232, 2848, 4352, 5476, 6412, 8640
Fuzzy . . . . . . : 23.0
The file is completely hidden from view and most antivirus products. It may belong to a rootkit.
This program is actively listening for inbound network connections.
The file is in use by one or more active processes.
The file is located in a folder that contains core operating system files from Windows. This is not typical for most programs and is only common to system tools, drivers and hacking utilities.
Starts automatically as a service during system bootup.
Time indicates that the file appeared recently on this computer.
This file's process is marked as system critical.
The file is protected by Windows File Protection (WFP). This is typical for critical Windows system files.
Program is code signed with a valid Authenticode certificate.
Startup
HKLM\SYSTEM\ControlSet001\Services\CDPUserSvc_21d415d8\
HKLM\SYSTEM\ControlSet001\Services\MessagingService_21d415d8\
HKLM\SYSTEM\ControlSet001\Services\OneSyncSvc_21d415d8\
HKLM\SYSTEM\ControlSet001\Services\PimIndexMaintenanceSvc_21d415d8\
HKLM\SYSTEM\ControlSet001\Services\UnistoreSvc_21d415d8\
HKLM\SYSTEM\ControlSet001\Services\UserDataSvc_21d415d8\
HKLM\SYSTEM\ControlSet001\Services\WpnUserService_21d415d8\
HKLM\SYSTEM\CurrentControlSet\Services\AJRouter\
HKLM\SYSTEM\CurrentControlSet\Services\AppIDSvc\
HKLM\SYSTEM\CurrentControlSet\Services\Appinfo\
HKLM\SYSTEM\CurrentControlSet\Services\AppMgmt\
HKLM\SYSTEM\CurrentControlSet\Services\AppReadiness\
HKLM\SYSTEM\CurrentControlSet\Services\AppXSvc\
HKLM\SYSTEM\CurrentControlSet\Services\AudioEndpointBuilder\
HKLM\SYSTEM\CurrentControlSet\Services\Audiosrv\
HKLM\SYSTEM\CurrentControlSet\Services\AxInstSV\
HKLM\SYSTEM\CurrentControlSet\Services\BDESVC\
HKLM\SYSTEM\CurrentControlSet\Services\BFE\
HKLM\SYSTEM\CurrentControlSet\Services\BITS\
HKLM\SYSTEM\CurrentControlSet\Services\BrokerInfrastructure\
HKLM\SYSTEM\CurrentControlSet\Services\Browser\
HKLM\SYSTEM\CurrentControlSet\Services\BthHFSrv\
HKLM\SYSTEM\CurrentControlSet\Services\bthserv\
HKLM\SYSTEM\CurrentControlSet\Services\CDPSvc\
HKLM\SYSTEM\CurrentControlSet\Services\CDPUserSvc\
HKLM\SYSTEM\CurrentControlSet\Services\CDPUserSvc_231c000e\
HKLM\SYSTEM\CurrentControlSet\Services\CertPropSvc\
HKLM\SYSTEM\CurrentControlSet\Services\ClipSVC\
HKLM\SYSTEM\CurrentControlSet\Services\CoreMessagingRegistrar\
HKLM\SYSTEM\CurrentControlSet\Services\CryptSvc\
HKLM\SYSTEM\CurrentControlSet\Services\CscService\
HKLM\SYSTEM\CurrentControlSet\Services\DcomLaunch\
HKLM\SYSTEM\CurrentControlSet\Services\DcpSvc\
HKLM\SYSTEM\CurrentControlSet\Services\defragsvc\
HKLM\SYSTEM\CurrentControlSet\Services\DeviceAssociationService\
HKLM\SYSTEM\CurrentControlSet\Services\DeviceInstall\
HKLM\SYSTEM\CurrentControlSet\Services\DevQueryBroker\
HKLM\SYSTEM\CurrentControlSet\Services\Dhcp\
HKLM\SYSTEM\CurrentControlSet\Services\DiagTrack\
HKLM\SYSTEM\CurrentControlSet\Services\DmEnrollmentSvc\
HKLM\SYSTEM\CurrentControlSet\Services\dmwappushservice\
HKLM\SYSTEM\CurrentControlSet\Services\Dnscache\
HKLM\SYSTEM\CurrentControlSet\Services\DoSvc\
HKLM\SYSTEM\CurrentControlSet\Services\dot3svc\
HKLM\SYSTEM\CurrentControlSet\Services\DPS\
HKLM\SYSTEM\CurrentControlSet\Services\DsmSvc\
HKLM\SYSTEM\CurrentControlSet\Services\DsSvc\
HKLM\SYSTEM\CurrentControlSet\Services\EapHost\
HKLM\SYSTEM\CurrentControlSet\Services\embeddedmode\
HKLM\SYSTEM\CurrentControlSet\Services\EntAppSvc\
HKLM\SYSTEM\CurrentControlSet\Services\EventLog\
HKLM\SYSTEM\CurrentControlSet\Services\EventSystem\
HKLM\SYSTEM\CurrentControlSet\Services\fdPHost\
HKLM\SYSTEM\CurrentControlSet\Services\FDResPub\
HKLM\SYSTEM\CurrentControlSet\Services\fhsvc\
HKLM\SYSTEM\CurrentControlSet\Services\FontCache\
HKLM\SYSTEM\CurrentControlSet\Services\FrameServer\
HKLM\SYSTEM\CurrentControlSet\Services\gpsvc\
HKLM\SYSTEM\CurrentControlSet\Services\hidserv\
HKLM\SYSTEM\CurrentControlSet\Services\HomeGroupListener\
HKLM\SYSTEM\CurrentControlSet\Services\HomeGroupProvider\
HKLM\SYSTEM\CurrentControlSet\Services\HvHost\
HKLM\SYSTEM\CurrentControlSet\Services\icssvc\
HKLM\SYSTEM\CurrentControlSet\Services\IKEEXT\
HKLM\SYSTEM\CurrentControlSet\Services\iphlpsvc\
HKLM\SYSTEM\CurrentControlSet\Services\irmon\
HKLM\SYSTEM\CurrentControlSet\Services\KtmRm\
HKLM\SYSTEM\CurrentControlSet\Services\LanmanServer\
HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\
HKLM\SYSTEM\CurrentControlSet\Services\lfsvc\
HKLM\SYSTEM\CurrentControlSet\Services\LicenseManager\
HKLM\SYSTEM\CurrentControlSet\Services\lltdsvc\
HKLM\SYSTEM\CurrentControlSet\Services\lmhosts\
HKLM\SYSTEM\CurrentControlSet\Services\LSM\
HKLM\SYSTEM\CurrentControlSet\Services\MapsBroker\
HKLM\SYSTEM\CurrentControlSet\Services\MessagingService\
HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_231c000e\
HKLM\SYSTEM\CurrentControlSet\Services\MpsSvc\
HKLM\SYSTEM\CurrentControlSet\Services\MSiSCSI\
HKLM\SYSTEM\CurrentControlSet\Services\NcaSvc\
HKLM\SYSTEM\CurrentControlSet\Services\NcbService\
HKLM\SYSTEM\CurrentControlSet\Services\NcdAutoSetup\
HKLM\SYSTEM\CurrentControlSet\Services\Netman\
HKLM\SYSTEM\CurrentControlSet\Services\netprofm\
HKLM\SYSTEM\CurrentControlSet\Services\NetSetupSvc\
HKLM\SYSTEM\CurrentControlSet\Services\NgcCtnrSvc\
HKLM\SYSTEM\CurrentControlSet\Services\NgcSvc\
HKLM\SYSTEM\CurrentControlSet\Services\NlaSvc\
HKLM\SYSTEM\CurrentControlSet\Services\nsi\
HKLM\SYSTEM\CurrentControlSet\Services\OneSyncSvc\
HKLM\SYSTEM\CurrentControlSet\Services\OneSyncSvc_231c000e\
HKLM\SYSTEM\CurrentControlSet\Services\p2pimsvc\
HKLM\SYSTEM\CurrentControlSet\Services\p2psvc\
HKLM\SYSTEM\CurrentControlSet\Services\PcaSvc\
HKLM\SYSTEM\CurrentControlSet\Services\PeerDistSvc\
HKLM\SYSTEM\CurrentControlSet\Services\PhoneSvc\
HKLM\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc\
HKLM\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc_231c000e\
HKLM\SYSTEM\CurrentControlSet\Services\pla\
HKLM\SYSTEM\CurrentControlSet\Services\PlugPlay\
HKLM\SYSTEM\CurrentControlSet\Services\PNRPAutoReg\
HKLM\SYSTEM\CurrentControlSet\Services\PNRPsvc\
HKLM\SYSTEM\CurrentControlSet\Services\PolicyAgent\
HKLM\SYSTEM\CurrentControlSet\Services\Power\
HKLM\SYSTEM\CurrentControlSet\Services\PrintNotify\
HKLM\SYSTEM\CurrentControlSet\Services\ProfSvc\
HKLM\SYSTEM\CurrentControlSet\Services\QWAVE\
HKLM\SYSTEM\CurrentControlSet\Services\RasAuto\
HKLM\SYSTEM\CurrentControlSet\Services\RasMan\
HKLM\SYSTEM\CurrentControlSet\Services\RemoteAccess\
HKLM\SYSTEM\CurrentControlSet\Services\RemoteRegistry\
HKLM\SYSTEM\CurrentControlSet\Services\RetailDemo\
HKLM\SYSTEM\CurrentControlSet\Services\RmSvc\
HKLM\SYSTEM\CurrentControlSet\Services\RpcEptMapper\
HKLM\SYSTEM\CurrentControlSet\Services\RpcSs\
HKLM\SYSTEM\CurrentControlSet\Services\SCardSvr\
HKLM\SYSTEM\CurrentControlSet\Services\ScDeviceEnum\
HKLM\SYSTEM\CurrentControlSet\Services\Schedule\
HKLM\SYSTEM\CurrentControlSet\Services\SCPolicySvc\
HKLM\SYSTEM\CurrentControlSet\Services\SDRSVC\
HKLM\SYSTEM\CurrentControlSet\Services\seclogon\
HKLM\SYSTEM\CurrentControlSet\Services\SENS\
HKLM\SYSTEM\CurrentControlSet\Services\SensorService\
HKLM\SYSTEM\CurrentControlSet\Services\SensrSvc\
HKLM\SYSTEM\CurrentControlSet\Services\SessionEnv\
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\
HKLM\SYSTEM\CurrentControlSet\Services\ShellHWDetection\
HKLM\SYSTEM\CurrentControlSet\Services\shpamsvc\
HKLM\SYSTEM\CurrentControlSet\Services\smphost\
HKLM\SYSTEM\CurrentControlSet\Services\SmsRouter\
HKLM\SYSTEM\CurrentControlSet\Services\SSDPSRV\
HKLM\SYSTEM\CurrentControlSet\Services\SstpSvc\
HKLM\SYSTEM\CurrentControlSet\Services\StateRepository\
HKLM\SYSTEM\CurrentControlSet\Services\stisvc\
HKLM\SYSTEM\CurrentControlSet\Services\StorSvc\
HKLM\SYSTEM\CurrentControlSet\Services\svsvc\
HKLM\SYSTEM\CurrentControlSet\Services\swprv\
HKLM\SYSTEM\CurrentControlSet\Services\SysMain\
HKLM\SYSTEM\CurrentControlSet\Services\SystemEventsBroker\
HKLM\SYSTEM\CurrentControlSet\Services\TabletInputService\
HKLM\SYSTEM\CurrentControlSet\Services\TapiSrv\
HKLM\SYSTEM\CurrentControlSet\Services\TermService\
HKLM\SYSTEM\CurrentControlSet\Services\Themes\
HKLM\SYSTEM\CurrentControlSet\Services\tiledatamodelsvc\
HKLM\SYSTEM\CurrentControlSet\Services\TimeBrokerSvc\
HKLM\SYSTEM\CurrentControlSet\Services\TrkWks\
HKLM\SYSTEM\CurrentControlSet\Services\tzautoupdate\
HKLM\SYSTEM\CurrentControlSet\Services\UmRdpService\
HKLM\SYSTEM\CurrentControlSet\Services\UnistoreSvc\
HKLM\SYSTEM\CurrentControlSet\Services\UnistoreSvc_231c000e\
HKLM\SYSTEM\CurrentControlSet\Services\upnphost\
HKLM\SYSTEM\CurrentControlSet\Services\UserDataSvc\
HKLM\SYSTEM\CurrentControlSet\Services\UserDataSvc_231c000e\
HKLM\SYSTEM\CurrentControlSet\Services\UserManager\
HKLM\SYSTEM\CurrentControlSet\Services\UsoSvc\
HKLM\SYSTEM\CurrentControlSet\Services\vmicguestinterface\
HKLM\SYSTEM\CurrentControlSet\Services\vmicheartbeat\
HKLM\SYSTEM\CurrentControlSet\Services\vmickvpexchange\
HKLM\SYSTEM\CurrentControlSet\Services\vmicrdv\
HKLM\SYSTEM\CurrentControlSet\Services\vmicshutdown\
HKLM\SYSTEM\CurrentControlSet\Services\vmictimesync\
HKLM\SYSTEM\CurrentControlSet\Services\vmicvmsession\
HKLM\SYSTEM\CurrentControlSet\Services\vmicvss\
HKLM\SYSTEM\CurrentControlSet\Services\W32Time\
HKLM\SYSTEM\CurrentControlSet\Services\WalletService\
HKLM\SYSTEM\CurrentControlSet\Services\WbioSrvc\
HKLM\SYSTEM\CurrentControlSet\Services\Wcmsvc\
HKLM\SYSTEM\CurrentControlSet\Services\wcncsvc\
HKLM\SYSTEM\CurrentControlSet\Services\WdiServiceHost\
HKLM\SYSTEM\CurrentControlSet\Services\WdiSystemHost\
HKLM\SYSTEM\CurrentControlSet\Services\WebClient\
HKLM\SYSTEM\CurrentControlSet\Services\Wecsvc\
HKLM\SYSTEM\CurrentControlSet\Services\WEPHOSTSVC\
HKLM\SYSTEM\CurrentControlSet\Services\wercplsupport\
HKLM\SYSTEM\CurrentControlSet\Services\WerSvc\
HKLM\SYSTEM\CurrentControlSet\Services\WiaRpc\
HKLM\SYSTEM\CurrentControlSet\Services\WinHttpAutoProxySvc\
HKLM\SYSTEM\CurrentControlSet\Services\Winmgmt\
HKLM\SYSTEM\CurrentControlSet\Services\WinRM\
HKLM\SYSTEM\CurrentControlSet\Services\wisvc\
HKLM\SYSTEM\CurrentControlSet\Services\WlanSvc\
HKLM\SYSTEM\CurrentControlSet\Services\wlidsvc\
HKLM\SYSTEM\CurrentControlSet\Services\workfolderssvc\
HKLM\SYSTEM\CurrentControlSet\Services\WPDBusEnum\
HKLM\SYSTEM\CurrentControlSet\Services\WpnService\
HKLM\SYSTEM\CurrentControlSet\Services\WpnUserService\
HKLM\SYSTEM\CurrentControlSet\Services\WpnUserService_231c000e\
HKLM\SYSTEM\CurrentControlSet\Services\wscsvc\
HKLM\SYSTEM\CurrentControlSet\Services\wuauserv\
HKLM\SYSTEM\CurrentControlSet\Services\wudfsvc\
HKLM\SYSTEM\CurrentControlSet\Services\WwanSvc\
HKLM\SYSTEM\CurrentControlSet\Services\XblAuthManager\
HKLM\SYSTEM\CurrentControlSet\Services\XblGameSave\
HKLM\SYSTEM\CurrentControlSet\Services\XboxNetApiSvc\
Network Ports
0.0.0.0:135
0.0.0.0:1537
0.0.0.0:1538
192.168.1.79:8905 111.221.29.107:443
192.168.1.79:8970 2.17.48.130:80
[/code]
