I used VirusTotal to scan file SECOH-QAD.dll it out a notice dangerous this ???

Anonymous
2016-07-22T05:22:03+00:00

I used VirusTotal to scan file SECOH-QAD.dll it out a notice dangerous this ???

SHA256: 0398221231cff97e1fdc03d357ac4610afb8f3cdde4c90a9ec4d7823b405699e
Tên tập tin: SECOH-QAD.dll
Tỷ lệ phát hiện: 18 / 54
Ngày phân tích: 2016-07-22 05:07:40 UTC ( 2 phút trước )

43

47

AVware Trojan.Win32.Generic!BT 20160722
AegisLab Nettool.Win64.Rpchook!c 20160721
Antiy-AVL RiskWare[NetTool:not-a-virus]/Win64.RPCHook 20160722
CAT-QuickHeal NetTool.RPCHook.r4 (Not a Virus) 20160721
ESET-NOD32 Win64/HackKMS.D potentially unsafe 20160722
GData Win64.Application.Agent.YQQKJO 20160722
Ikarus PUA.NetTool.RPCHook 20160721
Jiangmin NetTool.RPCHook.k 20160722
K7AntiVirus Hacktool ( 000047b11 ) 20160721
K7GW Hacktool ( 000047b11 ) 20160722
Kaspersky not-a-virus:NetTool.Win64.RPCHook.a 20160722
McAfee Generic HTool.b 20160721
McAfee-GW-Edition Generic HTool.b 20160722
NANO-Antivirus Riskware.Win64.HackKMS.dzkjpw 20160722
VIPRE Trojan.Win32.Generic!BT 20160722
ViRobot RPCHook.3584[h] 20160722
Yandex Riskware.NetTool! 20160721
nProtect Trojan/W32.Agent.3584.MQ 20160721
ALYac 20160722
AVG 20160722
Ad-Aware 20160722
AhnLab-V3 20160721
Alibaba 20160722
Arcabit 20160722
Avast 20160722
Avira (no cloud) 20160721
Baidu 20160721
BitDefender 20160722
Bkav 20160721
CMC 20160715
ClamAV 20160722
Comodo 20160722
Cyren 20160722
DrWeb 20160722
Emsisoft 20160722
F-Prot 20160722
F-Secure 20160722
Fortinet 20160722
Kingsoft 20160722
Malwarebytes 20160722
eScan 20160722
Microsoft 20160722
Panda 20160721
Qihoo-360 20160722
SUPERAntiSpyware 20160722
Sophos 20160722
Symantec 20160722
Tencent 20160722
TheHacker 20160720
TrendMicro 20160722
TrendMicro-HouseCall 20160722
VBA32 20160721
Zillya 20160721
Zoner 20160722
Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

84 answers

Sort by: Oldest
  1. Anonymous
    2016-08-17T03:56:40+00:00

    Thank you.

    Before when reinstalling Windows for me ask?

    I use Ccleaner, Revo Uninstaller to remove a the software out the machine but can not removed it:

    "A file error occurred while trying to remove the program"

    Please would you please help

    This is Registry its :

    Software GoldWave

    Key Name:          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GoldWave v6.21

    Class Name:        <NO CLASS>

    Last Write Time:   8/6/2016 - 4:24 PM

    Value 0

      Name:            DisplayName

      Type:            REG_SZ

      Data:            GoldWave v6.21

    Value 1

      Name:            DisplayVersion

      Type:            REG_SZ

      Data:            6.21

    Value 2

      Name:            UninstallString

      Type:            REG_SZ

      Data:            "C:\Program Files\GoldWave\unstall.exe" "GoldWave v6.21" "C:\Program Files\GoldWave\unstall.log"

    Value 3

      Name:            HelpLink

      Type:            REG_SZ

      Data:            http://www.goldwave.com

    Value 4

      Name:            Publisher

      Type:            REG_SZ

      Data:            GoldWave Inc.

    Value 5

      Name:            DisplayIcon

      Type:            REG_SZ

      Data:            C:\Program Files\GoldWave\unstall.exe

    Value 6

      Name:            EstimatedSize

      Type:            REG_DWORD

      Data:            0xc350

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2016-08-17T04:42:16+00:00

    Registry

    Was this answer helpful?

    0 comments No comments
  3. Monkey57 3,535 Reputation points
    2016-08-17T11:53:10+00:00

    If you Win10 Reset (remove everything), you dont need to worry about removing anything beforehand, it will all be removed on reset.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2016-08-17T12:23:39+00:00

    thank you

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2016-08-19T08:35:39+00:00

    Hello, sorry to bother you

    Today I opened PC up reinstalling Windows

    HitmanPro automatically scans and detects a file suspicious: svchotst.exe WRP 468 Serive

    svchost.exe what? delete it go yes affects system no?. I want to understand about it

    [code]

    HitmanPro 3.7.14.265

    www.hitmanpro.com

    Computer name . . . . : MAYTINH-1Q20GA5

       Windows . . . . . . . : 10.0.0.14393.X64/4

       User name . . . . . . : MAYTINH-1Q20GA5\MyPC

       UAC . . . . . . . . . : Enabled

       License . . . . . . . : Free

    Scan date . . . . . . : 2016-08-19 13:18:35

       Scan mode . . . . . . : Normal

       Scan duration . . . . : 7m 10s

       Disk access mode  . . : Direct disk access (SRB)

       Cloud . . . . . . . . : Internet

       Reboot  . . . . . . . : No

    Threats . . . . . . . : 0

       Traces  . . . . . . . : 219

    Objects scanned . . . : 1,714,816

       Files scanned . . . . : 26,345

       Remnants scanned  . . : 418,435 files / 1,270,036 keys

    Suspicious files ____________________________________________________________

    C:\WINDOWS\system32\svchost.exe

          Size . . . . . . . : 44,496 bytes

          Age  . . . . . . . : 12.3 days (2016-08-07 06:56:07)

          Entropy  . . . . . : 6.0

          SHA-256  . . . . . : 438B6CCD84F4DD32D9684ED7D58FD7D1E5A75FE3F3D12AB6C788E6BB0FFAD5E7

          Product  . . . . . : Microsoft® Windows® Operating System

          Publisher  . . . . : Microsoft Corporation

          Description  . . . : Host Process for Windows Services

          Version  . . . . . : 10.0.14393.0

          Copyright  . . . . : © Microsoft Corporation. All rights reserved.

          RSA Key Size . . . : 2048

          Service  . . . . . : WpnUserService_21d415d8

          Process Type . . . : Critical

          LanguageID . . . . : 1033

          Authenticode . . . : Valid

          Running processes  : 468, 488, 652, 868, 936, 972, 1076, 1512, 1704, 1748, 1828, 2208, 2224, 2232, 2848, 4352, 5476, 6412, 8640

          Fuzzy  . . . . . . : 23.0

             The file is completely hidden from view and most antivirus products. It may belong to a rootkit.

             This program is actively listening for inbound network connections.

             The file is in use by one or more active processes.

             The file is located in a folder that contains core operating system files from Windows. This is not typical for most programs and is only common to system tools, drivers and hacking utilities.

             Starts automatically as a service during system bootup.

             Time indicates that the file appeared recently on this computer.

             This file's process is marked as system critical.

             The file is protected by Windows File Protection (WFP). This is typical for critical Windows system files.

             Program is code signed with a valid Authenticode certificate.

          Startup

             HKLM\SYSTEM\ControlSet001\Services\CDPUserSvc_21d415d8\

             HKLM\SYSTEM\ControlSet001\Services\MessagingService_21d415d8\

             HKLM\SYSTEM\ControlSet001\Services\OneSyncSvc_21d415d8\

             HKLM\SYSTEM\ControlSet001\Services\PimIndexMaintenanceSvc_21d415d8\

             HKLM\SYSTEM\ControlSet001\Services\UnistoreSvc_21d415d8\

             HKLM\SYSTEM\ControlSet001\Services\UserDataSvc_21d415d8\

             HKLM\SYSTEM\ControlSet001\Services\WpnUserService_21d415d8\

             HKLM\SYSTEM\CurrentControlSet\Services\AJRouter\

             HKLM\SYSTEM\CurrentControlSet\Services\AppIDSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\Appinfo\

             HKLM\SYSTEM\CurrentControlSet\Services\AppMgmt\

             HKLM\SYSTEM\CurrentControlSet\Services\AppReadiness\

             HKLM\SYSTEM\CurrentControlSet\Services\AppXSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\AudioEndpointBuilder\

             HKLM\SYSTEM\CurrentControlSet\Services\Audiosrv\

             HKLM\SYSTEM\CurrentControlSet\Services\AxInstSV\

             HKLM\SYSTEM\CurrentControlSet\Services\BDESVC\

             HKLM\SYSTEM\CurrentControlSet\Services\BFE\

             HKLM\SYSTEM\CurrentControlSet\Services\BITS\

             HKLM\SYSTEM\CurrentControlSet\Services\BrokerInfrastructure\

             HKLM\SYSTEM\CurrentControlSet\Services\Browser\

             HKLM\SYSTEM\CurrentControlSet\Services\BthHFSrv\

             HKLM\SYSTEM\CurrentControlSet\Services\bthserv\

             HKLM\SYSTEM\CurrentControlSet\Services\CDPSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\CDPUserSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\CDPUserSvc_231c000e\

             HKLM\SYSTEM\CurrentControlSet\Services\CertPropSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\ClipSVC\

             HKLM\SYSTEM\CurrentControlSet\Services\CoreMessagingRegistrar\

             HKLM\SYSTEM\CurrentControlSet\Services\CryptSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\CscService\

             HKLM\SYSTEM\CurrentControlSet\Services\DcomLaunch\

             HKLM\SYSTEM\CurrentControlSet\Services\DcpSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\defragsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\DeviceAssociationService\

             HKLM\SYSTEM\CurrentControlSet\Services\DeviceInstall\

             HKLM\SYSTEM\CurrentControlSet\Services\DevQueryBroker\

             HKLM\SYSTEM\CurrentControlSet\Services\Dhcp\

             HKLM\SYSTEM\CurrentControlSet\Services\DiagTrack\

             HKLM\SYSTEM\CurrentControlSet\Services\DmEnrollmentSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\dmwappushservice\

             HKLM\SYSTEM\CurrentControlSet\Services\Dnscache\

             HKLM\SYSTEM\CurrentControlSet\Services\DoSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\dot3svc\

             HKLM\SYSTEM\CurrentControlSet\Services\DPS\

             HKLM\SYSTEM\CurrentControlSet\Services\DsmSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\DsSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\EapHost\

             HKLM\SYSTEM\CurrentControlSet\Services\embeddedmode\

             HKLM\SYSTEM\CurrentControlSet\Services\EntAppSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\EventLog\

             HKLM\SYSTEM\CurrentControlSet\Services\EventSystem\

             HKLM\SYSTEM\CurrentControlSet\Services\fdPHost\

             HKLM\SYSTEM\CurrentControlSet\Services\FDResPub\

             HKLM\SYSTEM\CurrentControlSet\Services\fhsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\FontCache\

             HKLM\SYSTEM\CurrentControlSet\Services\FrameServer\

             HKLM\SYSTEM\CurrentControlSet\Services\gpsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\hidserv\

             HKLM\SYSTEM\CurrentControlSet\Services\HomeGroupListener\

             HKLM\SYSTEM\CurrentControlSet\Services\HomeGroupProvider\

             HKLM\SYSTEM\CurrentControlSet\Services\HvHost\

             HKLM\SYSTEM\CurrentControlSet\Services\icssvc\

             HKLM\SYSTEM\CurrentControlSet\Services\IKEEXT\

             HKLM\SYSTEM\CurrentControlSet\Services\iphlpsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\irmon\

             HKLM\SYSTEM\CurrentControlSet\Services\KtmRm\

             HKLM\SYSTEM\CurrentControlSet\Services\LanmanServer\

             HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\

             HKLM\SYSTEM\CurrentControlSet\Services\lfsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\LicenseManager\

             HKLM\SYSTEM\CurrentControlSet\Services\lltdsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\lmhosts\

             HKLM\SYSTEM\CurrentControlSet\Services\LSM\

             HKLM\SYSTEM\CurrentControlSet\Services\MapsBroker\

             HKLM\SYSTEM\CurrentControlSet\Services\MessagingService\

             HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_231c000e\

             HKLM\SYSTEM\CurrentControlSet\Services\MpsSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\MSiSCSI\

             HKLM\SYSTEM\CurrentControlSet\Services\NcaSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\NcbService\

             HKLM\SYSTEM\CurrentControlSet\Services\NcdAutoSetup\

             HKLM\SYSTEM\CurrentControlSet\Services\Netman\

             HKLM\SYSTEM\CurrentControlSet\Services\netprofm\

             HKLM\SYSTEM\CurrentControlSet\Services\NetSetupSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\NgcCtnrSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\NgcSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\NlaSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\nsi\

             HKLM\SYSTEM\CurrentControlSet\Services\OneSyncSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\OneSyncSvc_231c000e\

             HKLM\SYSTEM\CurrentControlSet\Services\p2pimsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\p2psvc\

             HKLM\SYSTEM\CurrentControlSet\Services\PcaSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\PeerDistSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\PhoneSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc_231c000e\

             HKLM\SYSTEM\CurrentControlSet\Services\pla\

             HKLM\SYSTEM\CurrentControlSet\Services\PlugPlay\

             HKLM\SYSTEM\CurrentControlSet\Services\PNRPAutoReg\

             HKLM\SYSTEM\CurrentControlSet\Services\PNRPsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\PolicyAgent\

             HKLM\SYSTEM\CurrentControlSet\Services\Power\

             HKLM\SYSTEM\CurrentControlSet\Services\PrintNotify\

             HKLM\SYSTEM\CurrentControlSet\Services\ProfSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\QWAVE\

             HKLM\SYSTEM\CurrentControlSet\Services\RasAuto\

             HKLM\SYSTEM\CurrentControlSet\Services\RasMan\

             HKLM\SYSTEM\CurrentControlSet\Services\RemoteAccess\

             HKLM\SYSTEM\CurrentControlSet\Services\RemoteRegistry\

             HKLM\SYSTEM\CurrentControlSet\Services\RetailDemo\

             HKLM\SYSTEM\CurrentControlSet\Services\RmSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\RpcEptMapper\

             HKLM\SYSTEM\CurrentControlSet\Services\RpcSs\

             HKLM\SYSTEM\CurrentControlSet\Services\SCardSvr\

             HKLM\SYSTEM\CurrentControlSet\Services\ScDeviceEnum\

             HKLM\SYSTEM\CurrentControlSet\Services\Schedule\

             HKLM\SYSTEM\CurrentControlSet\Services\SCPolicySvc\

             HKLM\SYSTEM\CurrentControlSet\Services\SDRSVC\

             HKLM\SYSTEM\CurrentControlSet\Services\seclogon\

             HKLM\SYSTEM\CurrentControlSet\Services\SENS\

             HKLM\SYSTEM\CurrentControlSet\Services\SensorService\

             HKLM\SYSTEM\CurrentControlSet\Services\SensrSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\SessionEnv\

             HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\

             HKLM\SYSTEM\CurrentControlSet\Services\ShellHWDetection\

             HKLM\SYSTEM\CurrentControlSet\Services\shpamsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\smphost\

             HKLM\SYSTEM\CurrentControlSet\Services\SmsRouter\

             HKLM\SYSTEM\CurrentControlSet\Services\SSDPSRV\

             HKLM\SYSTEM\CurrentControlSet\Services\SstpSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\StateRepository\

             HKLM\SYSTEM\CurrentControlSet\Services\stisvc\

             HKLM\SYSTEM\CurrentControlSet\Services\StorSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\svsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\swprv\

             HKLM\SYSTEM\CurrentControlSet\Services\SysMain\

             HKLM\SYSTEM\CurrentControlSet\Services\SystemEventsBroker\

             HKLM\SYSTEM\CurrentControlSet\Services\TabletInputService\

             HKLM\SYSTEM\CurrentControlSet\Services\TapiSrv\

             HKLM\SYSTEM\CurrentControlSet\Services\TermService\

             HKLM\SYSTEM\CurrentControlSet\Services\Themes\

             HKLM\SYSTEM\CurrentControlSet\Services\tiledatamodelsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\TimeBrokerSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\TrkWks\

             HKLM\SYSTEM\CurrentControlSet\Services\tzautoupdate\

             HKLM\SYSTEM\CurrentControlSet\Services\UmRdpService\

             HKLM\SYSTEM\CurrentControlSet\Services\UnistoreSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\UnistoreSvc_231c000e\

             HKLM\SYSTEM\CurrentControlSet\Services\upnphost\

             HKLM\SYSTEM\CurrentControlSet\Services\UserDataSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\UserDataSvc_231c000e\

             HKLM\SYSTEM\CurrentControlSet\Services\UserManager\

             HKLM\SYSTEM\CurrentControlSet\Services\UsoSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\vmicguestinterface\

             HKLM\SYSTEM\CurrentControlSet\Services\vmicheartbeat\

             HKLM\SYSTEM\CurrentControlSet\Services\vmickvpexchange\

             HKLM\SYSTEM\CurrentControlSet\Services\vmicrdv\

             HKLM\SYSTEM\CurrentControlSet\Services\vmicshutdown\

             HKLM\SYSTEM\CurrentControlSet\Services\vmictimesync\

             HKLM\SYSTEM\CurrentControlSet\Services\vmicvmsession\

             HKLM\SYSTEM\CurrentControlSet\Services\vmicvss\

             HKLM\SYSTEM\CurrentControlSet\Services\W32Time\

             HKLM\SYSTEM\CurrentControlSet\Services\WalletService\

             HKLM\SYSTEM\CurrentControlSet\Services\WbioSrvc\

             HKLM\SYSTEM\CurrentControlSet\Services\Wcmsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\wcncsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\WdiServiceHost\

             HKLM\SYSTEM\CurrentControlSet\Services\WdiSystemHost\

             HKLM\SYSTEM\CurrentControlSet\Services\WebClient\

             HKLM\SYSTEM\CurrentControlSet\Services\Wecsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\WEPHOSTSVC\

             HKLM\SYSTEM\CurrentControlSet\Services\wercplsupport\

             HKLM\SYSTEM\CurrentControlSet\Services\WerSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\WiaRpc\

             HKLM\SYSTEM\CurrentControlSet\Services\WinHttpAutoProxySvc\

             HKLM\SYSTEM\CurrentControlSet\Services\Winmgmt\

             HKLM\SYSTEM\CurrentControlSet\Services\WinRM\

             HKLM\SYSTEM\CurrentControlSet\Services\wisvc\

             HKLM\SYSTEM\CurrentControlSet\Services\WlanSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\wlidsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\workfolderssvc\

             HKLM\SYSTEM\CurrentControlSet\Services\WPDBusEnum\

             HKLM\SYSTEM\CurrentControlSet\Services\WpnService\

             HKLM\SYSTEM\CurrentControlSet\Services\WpnUserService\

             HKLM\SYSTEM\CurrentControlSet\Services\WpnUserService_231c000e\

             HKLM\SYSTEM\CurrentControlSet\Services\wscsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\wuauserv\

             HKLM\SYSTEM\CurrentControlSet\Services\wudfsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\WwanSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\XblAuthManager\

             HKLM\SYSTEM\CurrentControlSet\Services\XblGameSave\

             HKLM\SYSTEM\CurrentControlSet\Services\XboxNetApiSvc\

          Network Ports

             0.0.0.0:135 

             0.0.0.0:1537 

             0.0.0.0:1538 

             192.168.1.79:8905 111.221.29.107:443

             192.168.1.79:8970 2.17.48.130:80

    [/code]

    Was this answer helpful?

    0 comments No comments