How to remove winserv.exe

winserv.exe

The module winserv.exe has been detected as Trojan.Sabsik

winserv.exe
Product Name:

System

Company Name:

tox

MD5: 3f4f5a6cb95047fea6102bd7d2226aa9
Size: 10 MB
First Published: 2022-07-14 23:21:03 (3 years ago)
Latest Published: 2025-08-26 23:03:16 (3 weeks ago)
Status: Trojan.Sabsik (on last analysis)
Analysis Date: 2025-08-26 23:03:16 (3 weeks ago)
%commonappdata%
%commonappdata%
%commonappdata%
%commonappdata%
%commonappdata%
%commonappdata%
%commonappdata%
%commonappdata%
%commonappdata%
%commonappdata%
50.6%
15.7%
5.1%
4.2%
3.2%
1.3%
1.3%
1.0%
1.0%
1.0%
1.0%
1.0%
1.0%
1.0%
1.0%
0.6%
0.6%
0.6%
0.6%
0.6%
0.6%
0.6%
0.6%
0.6%
0.6%
0.6%
0.6%
0.6%
0.6%
0.6%
0.3%
0.3%
0.3%
0.3%
Windows 10 96.5%
Windows 7 3.5%
Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x0077b96c

PE Sections:

Name Size of data MD5
.tls 10560512 2e7ca63fa88daeae7fd9830b8655abbd
.rsrc 92160 64ab199fce033650bbe20cf75c3e3597
.idata 22528 46c8ceb8f393fdd5b905455c1e58401f

More information:

Download GridinSoft Anti-Malware - Removal tool for winserv.exe