How to remove ProduKey.exe
- File Details
- Overview
- Analysis
ProduKey.exe
The module ProduKey.exe has been detected as Virtool.Presenoker
File Details
| Product Name: |
|
| Company Name: |
|
| MD5: |
66e3e2097c8aa5352fc56af3b6576184 |
| Size: |
125 KB |
| First Published: |
2020-07-22 04:51:12 (5 years ago) |
| Latest Published: |
2022-09-06 23:05:38 (3 years ago) |
| Status: |
Virtool.Presenoker (on last analysis) |
|
| Analysis Date: |
2022-09-06 23:05:38 (3 years ago) |
Overview
| %sysdrive%\progs |
| %sysdrive%\downloads\torrent\done\adminpe10_uefi\adminpe10_uefi\adminpe32\peprograms\nirsoft.exe\programs\nirsoft |
| %windir%\ltsvc |
| %sysdrive%\progs |
| %desktop% |
| %sysdrive%\data\sh\documents\job\alex |
| %sysdrive%\windowsprograms\windows office |
| %sysdrive%\windowsprograms\windows office |
| %sysdrive%\todo lo aprovechable con error de c\descargas\portables |
| %desktop% |
|
23.1% |
|
|
15.4% |
|
|
15.4% |
|
|
7.7% |
|
|
7.7% |
|
|
7.7% |
|
|
7.7% |
|
|
7.7% |
|
|
7.7% |
|
| Windows 10 |
84.6% |
|
| Windows 7 |
7.7% |
|
| Windows 8.1 |
7.7% |
|
Analysis
| Subsystem: |
Windows GUI |
| PE Type: |
pe |
| OS Bitness: |
64 |
| Image Base: |
0x0000000140000000 |
| Entry Address: |
0x00014400 |
| Name |
Size of data |
MD5 |
| .text |
80384 |
7767328f6d3c38b0d8301676da86e171 |
| .rdata |
16384 |
4ae12c0e6eb75007bc80c8a03074e8c8 |
| .data |
1024 |
762d54ed8c44f49974599a7fb029b1a0 |
| .pdata |
3072 |
cfadfc03535840304d368ec7eb0fad17 |
| .rsrc |
14848 |
743bead0009c92d9aeb22b38e53e4b5e |