Virustotal.coma gönderdim İşte Sonuç;
Virustotal is a service that analyzes suspicious files and URLs and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...
6 VT Community user(s) with a total of 1605 reputation credit(s) say(s) this sample is goodware. 2 VT Community user(s) with a total of 819 reputation credit(s) say(s) this sample is malware.
File name:
svchost.exe
Submission date:
2010-12-02 13:27:15 (UTC)
Current status:
queued queued analysing finished
Result:
1/ 43 (2.3%)
VT Community
goodware
Safety score: 66.2%
[url=#]Compact[/url]
Print results AntivirusVersionLast UpdateResultAhnLab-V32010.12.02.072010.12.02-AntiVir7.10.14.1682010.12.02-Antiy-AVL2.0.3.72010.12.02-Avast4.8.1351.02010.12.02-Avast55.0.677.02010.12.02-AVG9.0.0.8512010.12.02-BitDefender7.22010.12.02-CAT-QuickHeal11.002010.12.02-ClamAV0.96.4.02010.12.02-Command5.2.11.52010.12.01-Comodo69252010.12.02-DrWeb5.0.2.033002010.12.02-Emsisoft5.0.0.502010.12.02-eSafe7.0.17.02010.12.01Win32.TrojanHorseeTrust-Vet36.1.80142010.12.02-F-Prot4.6.2.1172010.12.01-F-Secure9.0.16160.02010.12.02-Fortinet4.2.254.02010.12.02-GData212010.12.02-IkarusT3.1.1.90.02010.12.02-Jiangmin13.0.9002010.12.02-K7AntiVirus9.69.31362010.12.01-Kaspersky7.0.0.1252010.12.02-McAfee5.400.0.11582010.12.02-McAfee-GW-Edition2010.1C2010.12.02-Microsoft1.64022010.12.02-NOD3256662010.12.02-Norman6.06.102010.12.02-nProtect2010-12-02.012010.12.02-Panda10.0.2.72010.12.01-PCTools7.0.3.52010.12.02-Prevx3.02010.12.02-Rising22.76.02.042010.12.02-Sophos4.60.02010.12.02-SUPERAntiSpyware4.40.0.10062010.12.02-Symantec20101.2.0.1612010.12.02-TheHacker6.7.0.1.0942010.12.01-TrendMicro9.120.0.10042010.12.02-TrendMicro-HouseCall9.120.0.10042010.12.02-VBA323.12.14.22010.12.02-VIPRE74762010.12.02-ViRobot2010.12.2.41812010.12.02-VirusBuster13.6.69.02010.12.01-
Additional information
Show all
MD5 : 54a47f6b5e09a77e61649109c6a08866
SHA1 : 4af001b3c3816b860660cf2de2c0fd3c1dfb4878
SHA256: 121118a0f5e0e8c933efd28c9901e54e42792619a8a3a6d11e1f0025a7324bc2
ssdeep: 384:eipYzV8555BUcKaJEEyKxC0exYQ1k3KFUOLg2JfvaW9C5bW9odW:3peIszaqEyKxCtxJk6F
bXaw
File size : 20992 bytes
First seen: 2009-07-22 12:30:01
Last seen : 2010-12-02 13:27:15
TrID: Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
sigcheck: publisher....: Microsoft Corporation
copyright....: (c) Microsoft Corporation. All rights reserved.
product......: Microsoft_ Windows_ Operating System
description..: Host Process for Windows Services
original name: svchost.exe
internal name: svchost.exe
file version.: 6.1.7600.16385 (win7_rtm.090713-1255)
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned
PEInfo: PE structure information[[ basic data ]]
entrypointaddress: 0x2104
timedatestamp....: 0x4A5BC100 (Mon Jul 13 23:19:28 2009)
machinetype......: 0x14c (I386)
[[ 4 section(s) ]]
name, viradd, virsiz, rawdsiz, ntropy, md5
.text, 0x1000, 0x39DC, 0x3A00, 6.29, 2eb5bad67734deb71cf023259153ef53
.data, 0x5000, 0x5A8, 0x600, 0.81, bdd64867dcbd8117aac049606aa40456
.rsrc, 0x6000, 0x810, 0xA00, 3.76, 66f21324fc812e3bf717c9aae7a151ee
.reloc, 0x7000, 0x3CC, 0x400, 6.40, 7d35466317c0fe1186bb026254385afe
[[ 8 import(s) ]]
msvcrt.dll: __wgetmainargs, _exit, _XcptFilter, exit, _initterm, _amsg_exit, __setusermatherr, memcpy, _controlfp, _except_handler4_common, _terminate@@YAXXZ, __set_app_type, __p__fmode, __p__commode, _cexit
API_MS_Win_Core_ProcessThreads_L1_1_0.dll: TerminateProcess, GetCurrentProcess, OpenProcessToken, GetCurrentProcessId, GetCurrentThreadId
KERNEL32.dll: LocalAlloc, CloseHandle, DelayLoadFailureHook, GetProcAddress, GetLastError, FreeLibrary, InterlockedCompareExchange, LoadLibraryExA, InterlockedExchange, Sleep, SetUnhandledExceptionFilter, GetModuleHandleA, QueryPerformanceCounter, GetTickCount, GetSystemTimeAsFileTime, UnhandledExceptionFilter, DeactivateActCtx, LoadLibraryExW, ActivateActCtx, LeaveCriticalSection, lstrcmpW, EnterCriticalSection, RegCloseKey, RegOpenKeyExW, HeapSetInformation, lstrcmpiW, lstrlenW, LCMapStringW, RegQueryValueExW, ReleaseActCtx, CreateActCtxW, ExpandEnvironmentStringsW, GetCommandLineW, ExitProcess, SetProcessAffinityUpdateMode, RegDisablePredefinedCacheEx, InitializeCriticalSection, GetProcessHeap, SetErrorMode, RegisterWaitForSingleObjectEx, LocalFree, HeapFree, WideCharToMultiByte, HeapAlloc
ntdll.dll: RtlAllocateHeap, RtlLengthRequiredSid, RtlSubAuthoritySid, RtlInitializeSid, RtlCopySid, RtlSubAuthorityCountSid, RtlInitializeCriticalSection, RtlSetProcessIsCritical, RtlImageNtHeader, RtlUnhandledExceptionFilter, EtwEventWrite, EtwEventEnabled, EtwEventRegister, RtlFreeHeap
API_MS_Win_Security_Base_L1_1_0.dll: SetSecurityDescriptorDacl, AddAccessAllowedAce, SetSecurityDescriptorOwner, SetSecurityDescriptorGroup, GetTokenInformation, InitializeSecurityDescriptor, GetLengthSid, InitializeAcl
API_MS_WIN_Service_Core_L1_1_0.dll: StartServiceCtrlDispatcherW, SetServiceStatus
API_MS_WIN_Service_winsvc_L1_1_0.dll: RegisterServiceCtrlHandlerW
RPCRT4.dll: RpcMgmtSetServerStackSize, I_RpcMapWin32Status, RpcServerUnregisterIf, RpcMgmtWaitServerListen, RpcMgmtStopServerListening, RpcServerUnregisterIfEx, RpcServerRegisterIf, RpcServerUseProtseqEpW, RpcServerListen
ExifTool:
file metadata
CharacterSet: Unicode
CodeSize: 14848
CompanyName: Microsoft Corporation
EntryPoint: 0x2104
FileDescription: Host Process for Windows Services
FileFlagsMask: 0x003f
FileOS: Windows NT 32-bit
FileSize: 20 kB
FileSubtype: 0
FileType: Win32 EXE
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
FileVersionNumber: 6.1.7600.16385
ImageVersion: 6.1
InitializedDataSize: 5120
InternalName: svchost.exe
LanguageCode: English (U.S.)
LegalCopyright: Microsoft Corporation. All rights reserved.
LinkerVersion: 9.0
MIMEType: application/octet-stream
MachineType: Intel 386 or later, and compatibles
OSVersion: 6.1
ObjectFileType: Executable application
OriginalFilename: svchost.exe
PEType: PE32
ProductName: Microsoft Windows Operating System
ProductVersion: 6.1.7600.16385
ProductVersionNumber: 6.1.7600.16385
Subsystem: Windows GUI
SubsystemVersion: 6.1
TimeStamp: 2009:07:14 01:19:28+02:00
UninitializedDataSize: 0