filesystemwatcher.vshost.exe

Microsoft Visual Studio 2008

Microsoft Corporation

This is a setup program which is used to install the application. This is installed with MSDN Library para Microsoft Visual Studio 2008 Express. The file has been seen being downloaded from s7808.chomikuj.pl and multiple other hosts.
Publisher:
Microsoft Corporation  (signed and verified)

Product:
Microsoft (R) Visual Studio (R) 2008

Description:
vshost.exe

Version:
9.0.21022.8

MD5:
99f9b3ab8971e77b5c93864ee0a7b97d

SHA-1:
5ddc58cfb6d68a03c4201889819163abcf0f4ec5

SHA-256:
c7b2e4e4fb2fcc44c953673ff57c3d14bdf5d2008f35e9a84c2a11735f2d268f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)
Whitelisted  (by digital signature)

Analysis date:
11/24/2024 8:23:33 AM UTC  (today)

File size:
14 KB (14,328 bytes)

Product version:
9.0.21022.8

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
vshost.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\release\filesystemwatcher.vshost.exe

Digital Signature
Authority:
Microsoft Corporation

Valid from:
8/23/2007 2:23:13 AM

Valid to:
2/23/2009 1:33:13 AM

Subject:
CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Issuer:
CN=Microsoft Code Signing PCA, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Serial number:
610F784D000000000003

File PE Metadata
Compilation timestamp:
11/7/2007 8:26:16 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
192:HSgRxBcWLVmWUo6oEQKPnEt2yt8mGafdjIafdjShj7NoVE8I:J72WhmWRnELKt8HafdjIafdjcj3F

Entry address:
0x2A5E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
3 KB (3,072 bytes)

The file filesystemwatcher.vshost.exe has been discovered within the following program.

3% remove it
 
Powered by Should I Remove It?

The file filesystemwatcher.vshost.exe has been seen being distributed by the following 33 URLs.

http://s7808.chomikuj.pl/File.aspx?e=RUiRwMMFRwdTDBjnsdNfZwpXpOk9cl__rHrSYz__UTRiLkvxM2zrdf-QpH4Jt51nM4-cSFm4g_numfZHd2GYPFBmV7ubwzEVAzDWSnVS9QGSfFafYfbsKIPllGHm18VWHb5xCaRu41KddCB1Kv1vmmIS8MBrVs4RtN_KqEZyW2A&pv=2

http://s7808.chomikuj.pl/File.aspx?e=RUiRwMMFRwdTDBjnsdNfZ6LHTndOFCKQLzI_Kjmw8GtlH1zXBwdaamsfLvvPBK8QN3IAX2B7eCFuhOib8gSKWgkIOcKaoEKO0R20x6Vjox5klT9szURvwEOEo6GL9IfIqG3AdFZVjPS2xBOXn9a5ewZqlyFbR_IVM49gRgRFDjM&pv=2

http://s7808.chomikuj.pl/File.aspx?e=RUiRwMMFRwdTDBjnsdNfZ-mer7KxI2FwP0bCndXWJe3_r_yToK3Jch-kv52_Gxsviokf89AWYWb1nI0waSwu9YCCUX6VDPaTTMDO-nNjaomsR1YHJX0_hsXpVSDC4vCprx44uR9XuA2GSZ2IMdeWf3dQbPxtNAFEohVm5lwzMvc&pv=2

https://github.com/tomazas/ledcube8x8x8/raw/e4e1cdb9897a778910ddebdeb8ad6c18ab22d58f/software/.../3D8_Win.vshost.exe

http://s7808.chomikuj.pl/File.aspx?e=RUiRwMMFRwdTDBjnsdNfZ_gByfQ5yLys2phawLMtHMxfcK4t0CBrm9Pn4VaMI9ASXLnDKUIwkCF4bPfZRCFwhVGksd8ZA1dINdiTy8OYxGO9mL2uQRPNxW0MFUn2SeVOR6zHl2lT2ESewmhds_HZM2KU95NIsMQMRqo1xDMV6Ec&pv=2

http://s7808.chomikuj.pl/File.aspx?e=RUiRwMMFRwdTDBjnsdNfZwpXpOk9cl__rHrSYz__UTSWNtp-9KdE_ESe9OKob2XEihrPx9uphmrEE_jqQu_sUDBcZgPwpmjwJGsohPcscMtrBvnEqEokzl9SCMW1JXISawfHQKtRuoGqerJfO2UjgTlE3q8u-qgxNfnMSLPlUa0&pv=2

http://s6863.chomikuj.pl/File.aspx?e=RUiRwMMFRwdTDBjnsdNfZwpXpOk9cl__rHrSYz__UTTi9zfLQ063sG2Hs3yDHOwtzUeDlWapcCtEiodWVGMqGf7a_QRrnUB8e8ptfcPe0hKamqXUGb3GoZtynF_NhdAFMeyOi_3P3r2Rrc1DScxfHzDlgMvr4cafBeRaC53070_zpOJMFu5QQ1XxBdovh8KK&pv=2

http://s7808.chomikuj.pl/File.aspx?e=RUiRwMMFRwdTDBjnsdNfZwpXpOk9cl__rHrSYz__UTSQAvIci6eYeme-d0eNKPf8NE3qS07DQ6dnv6Khqsp7P4tZnqmrByYoH35P3_7Z8phY80MDwEeqaNWd38_XaDnsBEt65uwZx098Sg-Ov2WrRt1clOT79BrCwHZk2r5vsS4&pv=2

http://s7808.chomikuj.pl/File.aspx?e=RUiRwMMFRwdTDBjnsdNfZwpXpOk9cl__rHrSYz__UTQ-b6tS-plOXnlIbv1gL_aWnT_PFM_H5q1g8C0hzX3cu7pSdIwFAAQ5pyVE3DkaE3zZLV1PvgfuU5kyLmXZRtKqvbYjyDs6Hu-fO2QbwILlT-1M0ZO-__c1qpzILY0u6AU&pv=2

http://s7808.chomikuj.pl/File.aspx?e=RUiRwMMFRwdTDBjnsdNfZ-3N8pXvO5UwZe3HISBwrkNOK0jdPxNkQQDIB2IV1q-RabecbNzOZRDZWtxAYBLMFWtphUve0OJBgx-XxnIZ1O1wnRlPLr7ua8Y6rq6iqSrbRWgNgdVUtxu-4Ei_N0oDpkGNT2vSiCS5uVnXhVrCByE&pv=2

http://s7808.chomikuj.pl/File.aspx?e=RUiRwMMFRwdTDBjnsdNfZ1gXBWIaKPWn1CHxoUTj3v4La5lO2XN-q1XO3DG2dWA3VNxt3tOeJb0_huPxaa3EeM8va7pWJEI6GXd2Lia39fRdnRTAEnsdojYParkS4oslO3devq_lR-B6TRAERGElYbe7EXIkHANui9e7I8JehlI&pv=2

http://s7808.chomikuj.pl/File.aspx?e=RUiRwMMFRwdTDBjnsdNfZ73KFGBZ3_dnb9d7D5gdPAEE3JQTpEAdQ6oSaugACSy5ogp1Uj4BTwvgER2OGIyBX18yvEVvYad2Mo8qAsqPlMNTypojL0ghPrQMC9yTXdeXu3aDGG_WsiIOwfabEQdwavbutJXVjB6zkiSPLgJYBDI&pv=2

http://s7808.chomikuj.pl/File.aspx?e=RUiRwMMFRwdTDBjnsdNfZ5TgDfPF-EiJ32G5KWlOEpZbz4bMBC2yd4ecAvBjEvojcFVCL3HZcENNlSuKbSVyHAJcIoC3IKl4LvDH81aV6hTFA_Q3UuiDuPp3K7jeAQ9LuamYGVogjdeoHqURIRexxD4P9jRSiInjO-_2KHgx2Hw&pv=2

ftp://24.235.104.187/Carpeta App tipo para sustituir/.../GConsular.vshost.exe

https://mega.nz/temporary/.../WwFGAS7S

http://s7808.chomikuj.pl/File.aspx?e=RUiRwMMFRwdTDBjnsdNfZ4OB0Gb70U4_qBSBgQVLZqDn4LsBPlPd-uk4AQotnrmMifGu4DWSSZzUL4IjIEJaH120eUwwwnMHFGZIZD5b65FoQQ5W2plPhQ6NBQvVBP5uhz7t4TgEnAMZfbUvZV5cI2JUDXkLFCJ_VYgKjxSLLpI&pv=2

http://s7808.chomikuj.pl/File.aspx?e=RUiRwMMFRwdTDBjnsdNfZ7k-mE_W-656DDoNetakZ-yCm-N2007wspZyuk-rwRTyFO_2AlLRyPrNAHPLsvM9TvXrMuafZz3FkGGHJu_gUKBnS18IkOiJEPtx7x0238Hdk9TuZqMU4eprIpVuAQzApSXymLcmrPxiW2gzszQIDes&pv=2

http://s7808.chomikuj.pl/File.aspx?e=RUiRwMMFRwdTDBjnsdNfZ3oPRWXyXGYnX0J29FbMjvfCf4gwJNO-LddJh6vO0FLjykl74IThsK3gDJeblv8lLvpDjs3WIjnuDc4zK21pFlFRlB7DQ4oqjkJiuKXqd3oGsHUBb0N4-8OCRyaDb4XqUUhjSy59K-ud__--hfrp9xg&pv=2

Latest 30 of 33 download URLs