How to remove ProduKey.exe
- File Details
- Overview
- Analysis
ProduKey.exe
The module ProduKey.exe has been detected as Virtool.Presenoker
File Details
Product Name: |
|
Company Name: |
|
MD5: |
66e3e2097c8aa5352fc56af3b6576184 |
Size: |
125 KB |
First Published: |
2020-07-22 04:51:12 (4 years ago) |
Latest Published: |
2022-09-06 23:05:38 (2 years ago) |
Status: |
Virtool.Presenoker (on last analysis) |
|
Analysis Date: |
2022-09-06 23:05:38 (2 years ago) |
Overview
%sysdrive%\progs |
%sysdrive%\downloads\torrent\done\adminpe10_uefi\adminpe10_uefi\adminpe32\peprograms\nirsoft.exe\programs\nirsoft |
%windir%\ltsvc |
%sysdrive%\progs |
%desktop% |
%sysdrive%\data\sh\documents\job\alex |
%sysdrive%\windowsprograms\windows office |
%sysdrive%\windowsprograms\windows office |
%sysdrive%\todo lo aprovechable con error de c\descargas\portables |
%desktop% |
|
23.1% |
|
|
15.4% |
|
|
15.4% |
|
|
7.7% |
|
|
7.7% |
|
|
7.7% |
|
|
7.7% |
|
|
7.7% |
|
|
7.7% |
|
Windows 10 |
84.6% |
|
Windows 7 |
7.7% |
|
Windows 8.1 |
7.7% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
64 |
Image Base: |
0x0000000140000000 |
Entry Address: |
0x00014400 |
Name |
Size of data |
MD5 |
.text |
80384 |
7767328f6d3c38b0d8301676da86e171 |
.rdata |
16384 |
4ae12c0e6eb75007bc80c8a03074e8c8 |
.data |
1024 |
762d54ed8c44f49974599a7fb029b1a0 |
.pdata |
3072 |
cfadfc03535840304d368ec7eb0fad17 |
.rsrc |
14848 |
743bead0009c92d9aeb22b38e53e4b5e |