Should I block it?

90%
90% of PCs block this file from running.
Possible reason:
Multiple malware detections

VersionsAdditional versions

0772c 50.00%
d38ae 50.00%
(Note, the developer publishes each variation of this file with the same version, but the hashes are unique.)

PE structurePE file structure

Show functions
Import table
msvcrt.dll
DllMain

svchost.exe

Remove svchost.exe
MD5:   d38aeeda5d1638e25715a2b67d44ba7d
SHA1:   5d3e7db9c99f8e2672d44c66739483eebef94c5a
SHA256:   50a4463e5ddbdfad509c8dd5dbca0858486b8c9af6ae2b89d463b937a582cf53
Warning 5 antivirus scanners has detected malware.

Overview

svchost.exe is malware that executes as a process with the local user's privileges. It is installed with a couple of know programs including Windows Internet Explorer 8 published by Microsoft Corporation and Bitcoin published by Bitcoin project.

DetailsDetails

File name:svchost.exe
Typical file path:C:\ProgramData\adob\svchost.exe
Size:6.33 MB (6,639,870 bytes)
Digital DNA
PE subsystem:Windows GUI
File packed:Yes
Code language:Microsoft Visual C++
.NET CLR:No
More details

ResourcesPrograms

The following programs will install this file
Bitcoin project
9% remove
Bitcoin uses peer-to-peer technology to operate with no central authority; managing transactions and the issuing of bitcoins is carried out collectively by the network. Through many of its unique properties, Bitcoin allows exciting uses that could not be covered by any previous payment systems. As a new user, you only need to choose a wallet that you will install on your computer or on your mobile phone. Once you have your wallet instal...
Microsoft Corporation
5% remove
Windows IE8 (Internet Explorer 8) is a web browser from Microsoft. IE8 contains many new features, including WebSlices and Accelerators (Accelerators are a form of selection-based search which allow a user to invoke an online service from any other page using only the mouse). The address bar features domain highlighting for added security so that the top-level domain is shown in black whereas the other parts of the URL are grayed out. I...
Network connections
  • [TCP] gb12.superseedbox.co.uk (94.23.216.171:8887)

  • MalwareMalware detections

    Based on 40+ industry antivirus scanners, 5 of them detected the following malware.
    Antivirus engineEngine versionDetection
    Emsisoft Anti-Malware 3.0.0.583 Trojan.Win32.CoinMiner (A)
    ESET NOD32 7.8564 Win32/BitCoinMiner.V
    Malwarebytes 1.75.0.1 Trojan.BitCoinMiner
    Symantec 20131.1.0.101 WS.Reputation.1
    Trend Micro HouseCall 9.700.0.1001 TROJ_GEN.F47V0612

    ResourcesResource utilization

    (Note: statistics below are averages based on a minimum sample size of 200 unique participants)
    Averages
     
    CPU
    Total CPU:0.00170369%
    0.028634%
    Kernel CPU:0.00131578%
    0.013761%
    User CPU:0.00038791%
    0.014873%
    Kernel CPU time:857,537,497 ms/min
    100,923,805ms/min
    Context switches:119/sec
    284/sec
    Memory
    Private memory:78.35 MB
    21.59 MB
    Private (maximum):54.85 MB
    Private (minimum):29.74 MB
    Non-paged memory:78.35 MB
    21.59 MB
    Virtual memory:178.02 MB
    140.96 MB
    Virtual memory (peak):181.77 MB
    169.69 MB
    Working set:30.19 MB
    18.61 MB
    Working set (peak):54.96 MB
    37.95 MB
    Resource allocations
    Threads:7
    12
    Handles:2748
    600
    GUI GDI count:4
    103
    GUI GDI peak:6
    142
    GUI USER count:3
    49
    GUI USER peak:3
    71

    BehaviorsProcess properties

    Integrety level:Medium
    Platform:64-bit
    Command line:"C:\users\user\appdata\roaming\activex\svchost.exe"
    Owner:User

    Windows OS versionsDistribution by Windows OS

    OS versiondistribution
    Windows 7 Ultimate 100.00%

    Distribution by countryDistribution by country

    Argentina installs about 50.00% of svchost.exe.

    OEM distributionDistribution by PC manufacturer

    PC Manufacturerdistribution
    ASUS 66.67%
    GIGABYTE 33.33%
    Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

    Download it for FREE