Alright i wanna start off by saying i know this has to be a malware already cause one, when i open services all the other programs running on my computer have a description this one doesn't.
This is what it says when i look at the details.
Service name: AtherosSvc
Display name: AtherosSvc
The description is blank, it doesn't say anything so that's why i'm not putting anything there, it's also makes it 10x times more weird.
Path to executable: C:\WINDOWS\System32\drivers\AdminService.exe
Startup type: It was (automatic) But i since disabled it.
Service Status: It was running but i stopped it.
And when i go to the (Log on) Section of the details of this program/file.
Log on as: (Local System Account)
I also checked everything else out about this program and for recovery on it says (Take no action) on First failure, second failure and subsequent failures.
Also for (Dependencies) it says nothing, like it has no dependencies no programs or anything depend on this, which i also found really strange.
I did a file search i searched up where this program was located, it was located in system32/drivers.
It was created on: June 26, 2018, 5:03:28 AM
Modified: June 26, 2018, 5:03:28 AM
Accessed: June 26, 2018, 5:03:28 AM
Also the size of this file is: 406 KB (416,072 bytes)
And, The size on disk is: 408 KB (417,792 bytes)
And it's an .exe file.
I don't know if any of this helps just including it to make sure this a legit file or something or if this information will help someone help me to figure out if this is a safe program/file or not.
I went to the details of the file and for copyright it says: Microsoft Corporation. All Rights reserved.
So if this a legit microsoft file by any chance than it's extremely sketchy,
Also the original file name is: SETUPAPI.DLL
And i already did a virus/malware full scan, with malware bytes, and i'm currently doing a full scan with windows defender, than i'm gonna do a full scan with bitdefender, so hopefully it detects something, but if anyone can help me out that would be greatly appreciated.
* Moved from virus & malware