How to remove __installer.exe
- File Details
- Overview
- Analysis
__installer.exe
The module __installer.exe has been detected as Risk.CoinMiner
File Details
Product Name: |
|
Company Name: |
|
MD5: |
c8854ce0855537d2602289948fc50cdd |
Size: |
40 MB |
First Published: |
2019-06-13 15:22:35 (5 years ago) |
Latest Published: |
2021-06-18 20:34:49 (3 years ago) |
Status: |
Risk.CoinMiner (on last analysis) |
|
Analysis Date: |
2021-06-18 20:34:49 (3 years ago) |
Overview
%appdata% |
%profile% |
%sysdrive%\windows.old\users\moonc\appdata\roaming |
%sysdrive%\windows.old\users\moonc\appdata\roaming\honey miner |
%appdata% |
%profile% |
%appdata% |
%appdata% |
%appdata% |
%profile% |
|
32.1% |
|
|
10.7% |
|
|
10.7% |
|
|
7.1% |
|
|
7.1% |
|
|
7.1% |
|
|
7.1% |
|
|
3.6% |
|
|
3.6% |
|
|
3.6% |
|
|
3.6% |
|
|
3.6% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x0000338f |
Name |
Size of data |
MD5 |
.text |
26624 |
2df06693054d4889a2db11a8fe1a5a85 |
.rdata |
5632 |
966a3835fd2d9407261ae78460c26dcc |
.data |
1536 |
db8f31a08a2242d80c29e1f9500c6527 |
.ndata |
0 |
00000000000000000000000000000000 |
.rsrc |
380416 |
b83dc8467f6858f684e1612edf4a4c96 |