How to remove 64l.exe
64l.exe
The module 64l.exe has been detected as Trojan.Agent
File Details
Product Name: | XMRig |
Company Name: | www.xmrig.com |
MD5: | f059ac16e84e24db20a36fc0171b4666 |
Size: | 508 KB |
First Published: | 2017-06-13 01:02:30 (7 years ago) |
Latest Published: | 2017-11-30 14:02:12 (7 years ago) |
Status: | Trojan.Agent (on last analysis) | |
Analysis Date: | 2017-11-30 14:02:12 (7 years ago) |
Common Places:
%appdata%\ieservise |
%appdata%\ie1servise |
%sysdrive%\temp |
%appdata%\appdata |
%localappdata%\temp |
%appdata%\wshshell |
%sysdrive%\windows |
File Names:
xmrig.exe |
64l.exe |
Geography:
35.0% | ||
15.0% | ||
15.0% | ||
10.0% | ||
10.0% | ||
5.0% | ||
5.0% | ||
5.0% |
OS Version:
Windows 7 | 80.0% | |
Windows 10 | 15.0% | |
Windows 8.1 | 5.0% |
Analysis
Subsystem: | Windows CUI |
PE Type: | pe |
OS Bitness: | 64 |
Image Base: | 0x0000000000400000 |
Entry Address: | 0x00001500 |
PE Sections:
Name | Size of data | MD5 |
.text | 377856 | 9e622b351bbd3c867d54650847e1683d |
.data | 1024 | 0aa6719c931ae6a9fdbf26f145c58a9d |
.rdata | 91136 | d01ad7a0e5a91c13f4d8d3ac5233fe71 |
.pdata | 11264 | ee98dd336ff7a0b8490dce61adb4316d |
.xdata | 11264 | 6ed82068f5cb8fee76d8d2879c22b1e0 |
.bss | 0 | 00000000000000000000000000000000 |
.idata | 8192 | 561237c83f2121cd06503a9abe723d42 |
.CRT | 512 | f60f11d68fcef8d36e26d5c419694eeb |
.tls | 512 | 9a3f968d8d65764256d4697a746d6951 |
.rsrc | 17408 | 7eba4f4462a8668b7d47238a6268baa0 |
More information:
Download GridinSoft
Anti-Malware - Removal tool for 64l.exe