How to remove $RLKNX83.exe
- File Details
- Overview
- Analysis
$RLKNX83.exe
The module $RLKNX83.exe has been detected as Trojan.CoinMiner
File Details
Product Name: |
|
Company Name: |
|
MD5: |
34e8029610483f74ec7b3bd419e77e52 |
Size: |
44 MB |
First Published: |
2018-02-23 12:09:12 (6 years ago) |
Latest Published: |
2018-03-18 15:08:46 (6 years ago) |
Status: |
Trojan.CoinMiner (on last analysis) |
|
Analysis Date: |
2018-03-18 15:08:46 (6 years ago) |
Overview
%sysdrive%\gog games\the witcher 3 wild hunt goty\bin |
%sysdrive%\oyunlar\the witcher 3 wild hunt goty\bin |
%sysdrive%\the witcher\the witcher 3 wild hunt goty\bin |
%sysdrive%\$recycle.bin |
witcher3.exe |
$RLKNX83.exe |
Windows 10 |
55.6% |
|
Windows 7 |
44.4% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
64 |
Image Base: |
0x0000000140000000 |
Entry Address: |
0x00e7a1d8 |
Name |
Size of data |
MD5 |
.text |
30165504 |
c2f29f67f98edd337c74ba6f82aaddd4 |
.rdata |
11599872 |
e6b1478c0a581cf5961730b434b68f38 |
.data |
1283584 |
43cd819937c3fb69e2b949a042258e17 |
.pdata |
1944576 |
8f724256276a92b09c454aa91249cfa5 |
.tls |
1024 |
0f343b0931126a20f133d67c2b018a3b |
_RDATA |
6144 |
9cb4b6d18bdd5c2de7a72e9a3a44f64d |
.rsrc |
472576 |
5b97ba0935a8f935660dbfdd856ec13d |
.reloc |
1035776 |
5eccccc971b193d2aaf1cd522f122853 |