Should I block it?
Yes, 98% block recommendation.
Possible reason:
Multiple malware detections
Additional versions
(Note, the developer publishes each variation of this file with the same version, but the hashes are unique.)
Relationships
Parent process
Child process
svchost.exe
| MD5: | 0772c4183891d46bf6ba1a3cb81d8203 |
| SHA1: | e1438dd1ddc8e48dbe42010e1f580be5544739a2 |
| SHA256: | 610d17e090643c1f9d47aff44ab96467e1b4ff578b48202443eb530e73225b0b |
Warning 18 antivirus scanners has detected malware.
Overview
Details
| File name: | svchost.exe |
| Typical file path: | C:\ProgramData\adob\svchost.exe |
| Size: | 393 KB (402,432 bytes) |
| Digital DNA |
| PE subsystem: | Windows GUI |
| File packed: | Yes |
| Code language: | Microsoft Visual C++ |
| .NET CLR: | No |
More details
Malware detections
Based on 40+ industry antivirus scanners, 18 of them detected the following malware.
| Antivirus engine | Engine version | Detection |
| Agnitum |
5.5.1.3 |
RiskTool.BitCoinMiner!twIyKEl7oM8 |
| Avira AntiVir |
7.11.61.38 |
TR/Agent.402432.39 |
| avast! |
6.0.1289.0 |
Win32:Malware-gen |
| AVG |
2014.0.3629 |
Generic30.CFLU.dropper |
| BitDefender |
7.2 |
Dropped:Trojan.Generic.KD.819110 |
| ESET NOD32 |
7.8010 |
a variant of Win32/BitCoinMiner.L |
| Fortinet |
5.0.43.0 |
W32/BitCoinMiner.L |
| F-Secure |
11.0.19020.35 |
Dropped:Trojan.Generic.KD.819110 |
| G Data |
13.6.22 |
Dropped:Trojan.Generic.KD.819110 |
| Ikarus |
T3.1.4.0.0 |
Trojan-Dropper.Delf |
| Kaspersky |
9.0.0.837 |
not-a-virus:RiskTool.Win32.BitCoinMiner.cgf |
| McAfee |
5.400.1158 |
Artemis!0772C4183891 |
| McAfee Gateway Anti-Malware |
v2012.1-dat |
Heuristic.BehavesLike.Win32.ModifiedUPX.C |
| eScan by MicroWorld |
12.0.250.0 |
Dropped:Trojan.Generic.KD.819110 |
| Panda Antivirus |
10.0.3.5 |
Trj/Agent.MIZ |
| Trend Micro |
9.740.0.1012 |
TROJ_GEN.RCBZ7AT |
| Trend Micro HouseCall |
9.700.0.1001 |
TROJ_GEN.RCBZ7AT |
| VIPRE Antivirus |
15544 |
Trojan.Win32.Generic!BT |
Resource utilization
(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
| CPU |
| Total CPU: | 0.00014513% | |
| Kernel CPU: | 0.00009199% | |
| User CPU: | 0.00005314% | |
| Kernel CPU time: | 780,005 ms/min | |
| Memory |
| Private memory: | 3.45 MB | |
| Private (maximum): | 7.53 MB | |
| Private (minimum): | 340 KB | |
| Non-paged memory: | 3.45 MB | |
| Virtual memory: | 61.4 MB | |
| Virtual memory (peak): | 65.79 MB | |
| Working set: | 340 KB | |
| Working set (peak): | 7.53 MB | |
| Resource allocations |
| Threads: | 2 | |
| Handles: | 154 | |
| GUI GDI count: | 6 | |
| GUI GDI peak: | 7 | |
| GUI USER count: | 2 | |
| GUI USER peak: | 2 | |
Process properties
Distribution by Windows OS
| OS version | distribution |
| Windows 7 Ultimate |
100.00% |
|
Distribution by country
Argentina installs about 50.00% of svchost.exe.
Distribution by PC manufacturer
| PC Manufacturer | distribution |
| ASUS |
66.67% |
|
| GIGABYTE |
33.33% |
|