How to remove IMG001.exe
IMG001.exe
The module IMG001.exe has been detected as Trojan.CoinMiner

File Details
MD5: | bd876c4fedf7aeb139d1b75f2c27e73b |
Size: | 3 MB |
First Published: | 2018-02-26 12:06:56 (7 years ago) |
Latest Published: | 2019-12-12 22:45:11 (5 years ago) |
Status: | Trojan.CoinMiner (on last analysis) | |
Analysis Date: | 2019-12-12 22:45:11 (5 years ago) |
Common Places:
%appdata% |
%sysdrive%\$recycle.bin |
%sysdrive% |
%desktop% |
%sysdrive%\avast! sandbox\s-1-5-21-4055872282-260757032-2104090241-1001\r61\img001.exe_{16a46e6b-bb77-11e8-909b-00242133aa9c}\c\users\влад\appdata\roaming |
%profile%\дминистратор\application data |
%appdata% |
%sysdrive%\$recycle.bin |
%appdata% |
File Names:
img001.exe |
IMG001.exe |
$RZZ4RHG.exe |
$RXEHWBM.exe |
Geography:
90.4% | ||
5.8% | ||
3.8% |
OS Version:
Windows 7 | 62.3% | |
Windows 8.1 | 20.8% | |
Windows 10 | 9.4% | |
Windows 8 | 3.8% | |
Windows XP | 3.8% |
Analysis
Subsystem: | Windows GUI |
PE Type: | pe |
OS Bitness: | 32 |
Image Base: | 0x00400000 |
Entry Address: | 0x000030de |
PE Sections:
Name | Size of data | MD5 |
.text | 23552 | 6d2ac949e509365289077f57a2394cc2 |
.rdata | 4608 | a2c7710fa66fcbb43c7ef0ab9eea5e9a |
.data | 1024 | 4fd7359a00726630d103f26d54f0c156 |
.ndata | 0 | 00000000000000000000000000000000 |
.rsrc | 61952 | 4bc950a2bcc82be430135f9e604ac420 |
More information:
Download GridinSoft
Anti-Malware - Removal tool for IMG001.exe
