svchost.exe

OLX

The application svchost.exe by OLX has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘TaskHost’. Although this file uses the name svchost.exe, this is NOT the Windows SvcHost (Service Host) distributed with the OS.
Publisher:
OLX  (signed and verified)

Version:
15.3.0.8

MD5:
d235245a59fcced9073b65a7e4bddbe0

SHA-1:
2dd4a55c72eafba186454e72352291cbcc9c8c20

SHA-256:
f889cbf495f7fb73055b0b52c1dd877ab743498911a6573531ff69b86dd44e7f

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/5/2024 11:00:05 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.OLX (M)
16.2.4.13

File size:
502.4 KB (514,488 bytes)

Product version:
15.3.0.8

Original file name:
utik.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\svchost.exe

Digital Signature
Signed by:

Authority:
OLX

Valid from:
10/16/2015 12:07:49 AM

Valid to:
10/16/2016 12:07:49 AM

Subject:
CN=www.olx.pt, O=OLX, L=Lisboa, S=Lisboa, C=PY

Issuer:
CN=www.olx.pt, O=OLX, L=Lisboa, S=Lisboa, C=PY

Serial number:
00CF6272F99AFC8D4B

File PE Metadata
Compilation timestamp:
1/29/2016 1:55:13 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
80.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:s17fbN778Kd6yTo4vHs6e9omAgYDZAnao2KygrAAhoMsT+kPGimHBr13zLfhvZC0:+7fR8mTo4vA7YDdo2KZrAA6Msi6m/nv

Entry address:
0x7E92E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
498.5 KB (510,464 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
TaskHost

Command:
"C:\users\{user}\appdata\roaming\svchost.exe"


Remove svchost.exe - Powered by Reason Core Security