How to remove button64.exe

button64.exe

The module button64.exe has been detected as Adware.Toolbar

button64.exe
Product Name:

Browser Extensions

Company Name:

S.p.i.g.o.t, I.n.c.

MD5: 7f166af141d19245ad467c6f7d3e281b
Size: 50 KB
First Published: 2017-06-01 10:08:45 (7 years ago)
Latest Published: 2018-11-13 19:12:10 (6 years ago)
Status: Adware.Toolbar (on last analysis)
Analysis Date: 2018-11-13 19:12:10 (6 years ago)
Signed By: Spigot, Inc.
Status: Valid
%appdata%\browserextensions
%appdata%\browser extensions
%appdata%
%sysdrive%\recuva drives h i j k\windows 7(recognized)(0)\users\administrator\appdata\roaming
%profile%\edra\application data
%sysdrive%\maikl-пк\backup set 2014-12-28 190011\backup files 2014-12-28 190011\backup files 11.zip\c\users\maikl\appdata\roaming
%sysdrive%\maikl-пк\backup set 2015-01-18 190003\backup files 2015-01-18 190003\backup files 9.zip\c\users\maikl\appdata\roaming
%sysdrive%\maikl-пк\backup set 2014-12-07 200201\backup files 2014-12-07 200201\backup files 8.zip\c\users\maikl\appdata\roaming
%sysdrive%\adwcleaner\quarantine\c\documents and settings\owner\application data
Button64.exe
button64.exe
A0192246.exe
Button64.exe.vir
41.4%
37.9%
6.9%
6.9%
3.4%
3.4%
Windows 10 55.2%
Windows 7 41.4%
Windows XP 3.4%
Subsystem: Windows CUI
PE Type: pe
OS Bitness: 64
Image Base: 0x0000000140000000
Entry Address: 0x000015e4

PE Sections:

Name Size of data MD5
.text 24576 abf895d0203014dda74156e9556b94b7
.rdata 11264 078b1796d6a8ac8ee739fe2923f58987
.data 4608 daef69a72d81a67c27eb9aeccb2ca8df
.pdata 1536 1b226b070d262ba04cbf7de4d7c8e514
.rsrc 1536 e9652e387f8c2d525582748ca67fc508
.reloc 1024 b9e22432410970a3f880ea27256a45ee

More information:

Download GridinSoft Anti-Malware - Removal tool for button64.exe