Author Topic: [RESOLVED]Svchost.exe..ohh! no virustotal results FP?  (Read 8880 times)

0 Members and 1 Guest are viewing this topic.

true indian

  • Guest
[RESOLVED]Svchost.exe..ohh! no virustotal results FP?
« on: January 21, 2012, 04:19:33 PM »
this is my system svchost.exe

its from:

c:\windows\system32\svchost.exe

is this a FP on virustotal?
https://www.virustotal.com/file/121118a0f5e0e8c933efd28c9901e54e42792619a8a3a6d11e1f0025a7324bc2/analysis/1327158269/

I investigated with comodo kill switch and found that this the only svchost running on my clean win7...

Whats the big deal with esafe?
« Last Edit: January 21, 2012, 05:25:04 PM by true indian »

Offline !Donovan

  • Web Analyst
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2219
    • The WAR Against Malware
Re: Svchost.exe..ohh! no virustotal results FP?
« Reply #1 on: January 21, 2012, 04:30:56 PM »
Interesting to read all the comments.

You can send a sample to virus [at] avast [dot] com for analysis.

You can also try uploading it to Comodo's Instant Malware Analyzer http://camas.comodo.com To see what it does.
Familiarize Yourself! | Educate Yourself! | Beautify Yourself! | Scan Yourself!
"People who say it cannot be done should not interrupt those who are doing it."

true indian

  • Guest
Re: Svchost.exe..ohh! no virustotal results FP?
« Reply #2 on: January 21, 2012, 04:34:36 PM »
Comodo online file analyzer says its a not a excutable file....when i put it from my comodo defence+ for online lookup it says the file is safe...


comodo kill switch also tells me this is the only svchost on my win7 and it is legitimate...


threatexpert report:
http://www.threatexpert.com/report.aspx?md5=54a47f6b5e09a77e61649109c6a08866
« Last Edit: January 21, 2012, 04:39:21 PM by true indian »

Offline !Donovan

  • Web Analyst
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2219
    • The WAR Against Malware
Re: Svchost.exe..ohh! no virustotal results FP?
« Reply #3 on: January 21, 2012, 04:38:03 PM »
Comodo online file analyzer says its a not a excutable file....when i put it from my comodo defence+ for online lookup it says the file is safe...
Did you try sending it to avast yet?


Also:
Quote
Dropped file from trojan downloader. Download url ; hxxp://russian-post.net/load/load.exe
#malware
Posted 1 year, 4 months ago by remixed
https://www.virustotal.com/user/remixed/

A search for this reveals a lot of hits.
« Last Edit: January 21, 2012, 04:39:50 PM by Donovansrb10 »
Familiarize Yourself! | Educate Yourself! | Beautify Yourself! | Scan Yourself!
"People who say it cannot be done should not interrupt those who are doing it."

true indian

  • Guest
Re: Svchost.exe..ohh! no virustotal results FP?
« Reply #4 on: January 21, 2012, 04:40:23 PM »
my threatexpert report doesnt report any malware...

i have sent the file many times before but it has been found as clean...
« Last Edit: January 21, 2012, 04:42:57 PM by true indian »

Offline !Donovan

  • Web Analyst
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2219
    • The WAR Against Malware
Re: Svchost.exe..ohh! no virustotal results FP?
« Reply #5 on: January 21, 2012, 04:44:03 PM »
Probable eSafe fp

First seen by VirusTotal
2009-07-22 12:30:01 UTC ( 2 years, 6 months ago )

Last seen by VirusTotal
2012-01-21 15:04:29 UTC ( 36 minutes ago )
Familiarize Yourself! | Educate Yourself! | Beautify Yourself! | Scan Yourself!
"People who say it cannot be done should not interrupt those who are doing it."

true indian

  • Guest
Re: Svchost.exe..ohh! no virustotal results FP?
« Reply #6 on: January 21, 2012, 04:45:32 PM »
I have asked essexboy to take a look at the Vt report and this topic...lets see what he has to say....

probably this thing has even been reported at comodo forums...google search revealed it....that has been done a long while ago so they have found the file to be clean and legit.

i saw even many people on the forums have also reported it to avast! and the file hasnt been reported as malware...it is clean and legit even according to threat expert..

according to kill switch my svchost is connecting to the dhcp and event log....and to the windows update service...remote address for my svchost doesnt exist phew! ;)
« Last Edit: January 21, 2012, 04:52:24 PM by true indian »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37650
  • F-Secure user
Re: Svchost.exe..ohh! no virustotal results FP?
« Reply #7 on: January 21, 2012, 04:53:23 PM »
it is a eSafe false positive


First seen by VirusTotal
 2009-07-22 12:30:01 UTC ( 2 years, 6 months ago )
Last seen by VirusTotal
 2012-01-21 15:04:29 UTC ( 46 minutes ago )

Offline !Donovan

  • Web Analyst
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2219
    • The WAR Against Malware
Re: Svchost.exe..ohh! no virustotal results FP?
« Reply #8 on: January 21, 2012, 04:55:24 PM »
according to kill switch my svchost is connecting to the dhcp and event log....and to the windows update service...remote address for my svchost doesnt exist phew! ;)
Glad to see your problem is solved. :)

@Pondus

Good job for repeating every word I said. ;) ;D
Familiarize Yourself! | Educate Yourself! | Beautify Yourself! | Scan Yourself!
"People who say it cannot be done should not interrupt those who are doing it."

true indian

  • Guest
Re: Svchost.exe..ohh! no virustotal results FP?
« Reply #9 on: January 21, 2012, 04:56:47 PM »
Yup! its sure safe and legit ;D

So my system is clean.
« Last Edit: January 21, 2012, 04:59:21 PM by true indian »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37650
  • F-Secure user
Re: Svchost.exe..ohh! no virustotal results FP?
« Reply #10 on: January 21, 2012, 04:58:02 PM »
Quote
Good job for repeating every word I said.
yes...but he did not seem to hear what you say.....red letters scream louder   ;D

DonZ63

  • Guest
Re: Svchost.exe..ohh! no virustotal results FP?
« Reply #11 on: January 21, 2012, 05:00:21 PM »
Here's the detail on svchost.exe on my WIN 7 x64 SP1 installation. My size is 26.5K and has not changed from initial installation it appears.


true indian

  • Guest
Re: Svchost.exe..ohh! no virustotal results FP?
« Reply #12 on: January 21, 2012, 05:00:32 PM »
Quote
Good job for repeating every word I said.
yes...but he did not seem to hear what you say.....red letters scream louder   ;D


I reported this as FP to esafe long ago but they dont seem to remove the detection...poor tech support  :'(

true indian

  • Guest
Re: Svchost.exe..ohh! no virustotal results FP?
« Reply #13 on: January 21, 2012, 05:04:13 PM »
Mine is little smaller 20.5 KB


Not changed from 14 july 2009  :o

LOL! that time i didnt even have this laptop...

Not accessed since 14 july 2009  ;D
« Last Edit: January 21, 2012, 05:13:14 PM by true indian »

Offline !Donovan

  • Web Analyst
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2219
    • The WAR Against Malware
Re: Svchost.exe..ohh! no virustotal results FP?
« Reply #14 on: January 21, 2012, 05:22:05 PM »
Quote
Good job for repeating every word I said.
yes...but he did not seem to hear what you say.....red letters scream louder   ;D
Okay, so I just have to use RED letters from now on and Oindian will 'hear my cry'? ;D
Familiarize Yourself! | Educate Yourself! | Beautify Yourself! | Scan Yourself!
"People who say it cannot be done should not interrupt those who are doing it."