How to remove 32l.exe
32l.exe
The module 32l.exe has been detected as Trojan.Agent
File Details
Product Name: | XMRig |
Company Name: | www.xmrig.com |
MD5: | 03d8137e7cefbbe1e27fb6556323db1f |
Size: | 615 KB |
First Published: | 2017-06-14 23:10:31 (7 years ago) |
Latest Published: | 2018-03-16 18:15:51 (6 years ago) |
Status: | Trojan.Agent (on last analysis) | |
Analysis Date: | 2018-03-16 18:15:51 (6 years ago) |
Common Places:
%appdata%\ie1servise |
%appdata%\ieservise |
%localappdata%\temp |
%appdata%\wshshell |
%appdata% |
%sysdrive%\o9hycd8li1pn7dj\backup set 2017-12-17 192809\backup files 2017-12-31 190002\backup files 16.zip\c\users\administrator\appdata\roaming |
File Names:
xmrig32.exe |
32l.exe |
Geography:
36.8% | ||
31.6% | ||
21.1% | ||
5.3% | ||
5.3% |
OS Version:
Windows 7 | 94.7% | |
Windows 10 | 5.3% |
Analysis
Subsystem: | Windows CUI |
PE Type: | pe |
OS Bitness: | 32 |
Image Base: | 0x00400000 |
Entry Address: | 0x000014e0 |
PE Sections:
Name | Size of data | MD5 |
.text | 465920 | a79eda5cba76d555cc8b59ebd2f71e80 |
.data | 1024 | 316dd3cb2e25956e2a43506cd6be4273 |
.rdata | 87552 | 565fe74aaf30d42f02a8089b8a41f3f9 |
/4 | 50176 | a2cfe2e5cb865d96a0c26f0656d55d19 |
.bss | 0 | 00000000000000000000000000000000 |
.idata | 6144 | d27846fb6cd51daba5dc1d58117686b8 |
.CRT | 512 | 8d6c1a4382d6c543029f46eb70d6b734 |
.tls | 512 | 00eaa9c89117ce67fb8e781a716d60c8 |
.rsrc | 17408 | ad2a7af1ec542f353ccdc120ef1ebfcc |
More information:
Download GridinSoft
Anti-Malware - Removal tool for 32l.exe