sppsvc.exe
Microsoft Software Protection Platform Service by Microsoft Corporation (Signed)
| Version:    | 6.2.9200.16384 (win8_rtm.120725-1247) | 
| MD5:    | d9e859f4b29377854e1ab0f302824e1c | 
| SHA1:    | b82b3bf75792905d8d23badd25bfd0740c55a79d | 
| SHA256:    | 14d9639204c0af1fe8a06865bff9ff4b978ee42c02c774c5fa9f2bea9f75676c | 
This is a Windows system installed file with Windows File Protection (WFP) enabled.
Warning 4 antivirus scanners has detected malware.
Overview
sppsvc.exe is malware that runs as a service under the name Ochrana softwaru (sppsvc) with extensive SYSTEM privileges (full administrator access). The file is digitally signed by Microsoft Corporation. This version is installed on Windows 8 and is compiled as a 32 bit program.
Details
| File name: | sppsvc.exe | 
| Publisher: | Microsoft Corporation | 
| Product name: | Microsoft Software Protection Platform Service | 
| Description: | Microsoft® Windows® Operating System | 
| Typical file path: | C:\Windows\System32\sppsvc.exe | 
| Original name: | sppsvc.exe.mui | 
| File version: | 6.2.9200.16384 (win8_rtm.120725-1247) | 
| Product version: | 6.2.9200.16384 | 
| Size: | 10 KB (10,240 bytes) | 
| Certificate | 
| Issued to: | Microsoft Corporation | 
| Authority (CA): | Microsoft Corporation | 
| Expiration date: | Tuesday, July 9, 2013 | 
| Digital DNA | 
| PE subsystem: | Windows Console | 
| Entropy: | 7.357806 | 
| File packed: | No | 
| Code language: | Microsoft Visual C++ | 
| .NET CLR: | No | 
More details
Behaviors
Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
- SLSvc
 
- 'sppsvc'  (Software Protection)
 
Malware detections
Based on 40+ industry antivirus scanners, 4 of them detected the following malware.
| Antivirus engine | Engine version | Detection | 
| Comodo Internet Security | 
15862 | 
UnclassifiedMalware | 
| McAfee | 
5.400.1158 | 
GenericTRA-BS!D9E859F4B293 | 
| McAfee Gateway Anti-Malware | 
v2012.1-dat | 
GenericTRA-BS!D9E859F4B293 | 
| Trend Micro HouseCall | 
9.700.0.1001 | 
TROJ_GEN.F47V1215 | 
Resource utilization
(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
| CPU | 
| Total CPU: | 0.00000399% |  | 
| Kernel CPU: | 0.00000399% |  | 
| Kernel CPU time: | 6 ms/min |  | 
| CPU cycles: | 321/sec |  | 
| Memory | 
| Private memory: | 597.23 KB |  | 
| Private (maximum): | 1.93 MB |  | 
| Private (minimum): | 1.22 MB |  | 
| Non-paged memory: | 597.23 KB |  | 
| Virtual memory: | 17.77 MB |  | 
| Virtual memory (peak): | 19.55 MB |  | 
| Working set: | 1.25 MB |  | 
| Working set (peak): | 2.58 MB |  | 
| Page faults: | 983/min |  | 
| I/O | 
| I/O read transfer: | 11 Bytes/sec |  | 
| I/O read operations: | 1/sec |  | 
| I/O other transfer: | 0 Bytes/sec |  | 
| I/O other operations: | 1/sec |  | 
| Resource allocations | 
| Threads: | 2 |  | 
| Handles: | 47 |  | 
 
Process properties
| Integrety level: | System | 
| Platform: | 32-bit | 
| Command line: | C:\windows\sppsvc.exe | 
| Owner: | SYSTEM | 
| Windows Service | 
| Service name: | sppsvc | 
| Display name: | Ochrana softwaru | 
| Description: | “Gjør det mulig å laste ned, installere og aktivere digitale lisenser for Windows og Windows-programmer. Hvis tjenesten deaktiveres, kan det hende at operativsystemet og lisensierte programmer kjøres i varslingsmodus. Det anbefales på det sterkeste at du ikke deaktiverer tjenesten for programvarebeskyttelse.” | 
| Type: | Win32OwnProcess | 
| Parent process: | services.exe (by Microsoft) | 
Distribution by Windows OS
| OS version | distribution | 
| Windows 7 Home Premium | 
34.00% | 
 | 
| Windows 8.1 | 
17.00% | 
 | 
| Windows 7 Ultimate | 
15.50% | 
 | 
| Windows 8.1 Pro | 
7.50% | 
 | 
| Windows 7 Professional | 
7.00% | 
 | 
| Windows 8 | 
3.50% | 
 | 
| Windows 8.1 Single Language | 
3.50% | 
 | 
| Windows 8 Pro | 
3.00% | 
 | 
| Windows 8 Single Language | 
2.50% | 
 | 
| Windows 8.1 Pro with Media Center | 
2.00% | 
 | 
| Windows 7 Home Basic | 
1.50% | 
 | 
| Windows 8 Enterprise N | 
1.00% | 
 | 
| Windows 8.1 N | 
0.50% | 
 | 
| Windows Seven Black Edition | 
0.50% | 
 | 
| Windows 8.1 Enterprise Evaluation | 
0.50% | 
 | 
| Windows 8 Enterprise | 
0.50% | 
 | 
Distribution by country
United States installs about 45.23% of Microsoft Software Protection Platform Service.
Distribution by PC manufacturer
| PC Manufacturer | distribution | 
| Dell | 
18.90% | 
 | 
| Hewlett-Packard | 
18.50% | 
 | 
| ASUS | 
18.11% | 
 | 
| Acer | 
12.60% | 
 | 
| Toshiba | 
11.02% | 
 | 
| Lenovo | 
8.66% | 
 | 
| Sony | 
3.94% | 
 | 
| Intel | 
2.36% | 
 | 
| Samsung | 
1.97% | 
 | 
| GIGABYTE | 
1.97% | 
 | 
| Alienware | 
1.18% | 
 | 
| Medion | 
0.79% | 
 |