cchservice.exe

Salfeld Computer GmbH

It runs as a separate (within the context of its own process) windows Service named “Windows-CCHook-Service”.
Publisher:
Salfeld Computer  (signed by Salfeld Computer GmbH)

Description:
Salfeld Security Service

Version:
2.420.0.0

MD5:
6d172e30792f35df2486cf09a9235a3a

SHA-1:
ab0a202b0e037569dfc432979b7b6f3358a493f0

SHA-256:
aa384d464a50b467db867cbd585c633b6d5958baa423a621db2601d7a85b0008

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
11/27/2024 9:43:56 AM UTC  (today)

Scan engine
Detection
Engine version

IKARUS anti.virus
Trojan-Dropper.Delf
t3scan.1.1.97.0

Vba32 AntiVirus
Signed-Trojan.Win32.Delf.bet
3.12.14.3

File size:
226.7 KB (232,176 bytes)

Product version:
1.0.0.0

Copyright:
Salfeld Computer

File type:
Executable application (Win32 EXE)

Language:
German (Germany)

Common path:
C:\windows\syswow64\cchservice.exe

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
7/12/2006 2:00:00 AM

Valid to:
7/13/2007 1:59:59 AM

Subject:
CN=Salfeld Computer GmbH, OU=Security, O=Salfeld Computer GmbH, L=Reutlingen, S=BW, C=DE

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
7C51D33C549B5FEF47FBEA8C181362C0

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
3072:J+v8LTf2aOji6XBenHsba3dAb5FXoRsopc6wz07QmjMO6nkm2wUZpbZbTvMyPUu8:Y+POjLgsbslc6J7QmGkDYg+EYa+8Xri

Entry address:
0x2F42C

Entry point:
55, 8B, EC, 83, C4, E0, 53, 56, 57, 33, C0, 89, 45, E4, 89, 45, E0, 89, 45, EC, 89, 45, E8, B8, 7C, F2, 42, 00, E8, D3, 69, FD, FF, 33, C0, 55, 68, B9, F5, 42, 00, 64, FF, 30, 64, 89, 20, E8, 24, 77, FF, FF, 85, C0, 0F, 84, 31, 01, 00, 00, 33, C0, 55, 68, 06, F5, 42, 00, 64, FF, 30, 64, 89, 20, 6A, 00, 8D, 45, EC, E8, 1C, 9C, FE, FF, 8D, 45, EC, BA, D0, F5, 42, 00, E8, C7, 4B, FD, FF, 8B, 45, EC, E8, B7, 4D, FD, FF, 50, 8D, 45, E8, E8, FE, 9B, FE, FF, 8D, 45, E8, BA, E8, F5, 42, 00, E8, A9, 4B, FD, FF, 8B...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
186 KB (190,464 bytes)

Service
Display name:
Windows-CCHook-Service

Description:
Provides routines for advanced security control for Salfeld Security Software.

Type:
Win32OwnProcess


Scan cchservice.exe - Powered by Reason Core Security