How to remove FunSpace.Update.Process.exe
- File Details
- Overview
- Analysis
FunSpace.Update.Process.exe
The module FunSpace.Update.Process.exe has been detected as Trojan.LoadMoney
File Details
Product Name: |
|
Company Name: |
|
MD5: |
1ee94a87788d24cb8b5fa96cd0f89837 |
Size: |
472 KB |
First Published: |
2017-08-14 22:03:46 (7 years ago) |
Latest Published: |
2020-08-22 12:37:51 (4 years ago) |
Status: |
Trojan.LoadMoney (on last analysis) |
|
Analysis Date: |
2020-08-22 12:37:51 (4 years ago) |
Overview
%appdata%\funspace\shadow\funspace.update |
%appdata%\funspace\vkmusicupd |
%appdata%\funspace\shadow |
%sysdrive%\adwcleaner\quarantine\files\unooayerrdzlkhzpjmbbbhyboigfjgok\shadow |
%sysdrive%\adwcleaner\quarantine\files\unooayerrdzlkhzpjmbbbhyboigfjgok |
%profile%\dmin\application data\funspace\shadow |
%profile%\dmin\application data\funspace |
%appdata%\funspace |
%appdata%\funspace\shadow |
Windows 7 |
50.0% |
|
Windows 10 |
25.0% |
|
Windows XP |
16.7% |
|
Windows 8.1 |
8.3% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x0007679e |
MVID: |
db03d1f2-79c4-410e-aeeb-a41351dc2d99 |
Typelib ID: |
f1e0f153-99cc-4a0c-b450-17b1d2428417 |
Name |
Size of data |
MD5 |
.text |
477184 |
43e190f67e34edd4bce91e032c6bfe30 |
.rsrc |
2048 |
c1f5c17021eca1583fa0341bb5c7a0f2 |
.reloc |
512 |
e3a03a47907f1ec1365eda1cf0b9fe14 |