How to remove conhost_wz.exe
- File Details
- Overview
- Analysis
conhost_wz.exe
The module conhost_wz.exe has been detected as Trojan.CoinMiner
File Details
| Product Name: |
|
| Company Name: |
|
| MD5: |
9b890314cd7cc12b250f1e502c2bc811 |
| Size: |
4 MB |
| First Published: |
2024-06-17 23:00:48 (2 years ago) |
| Latest Published: |
2024-06-17 23:05:17 (2 years ago) |
| Status: |
Trojan.CoinMiner (on last analysis) |
|
| Analysis Date: |
2024-06-17 23:05:17 (2 years ago) |
Overview
| Signed By: |
Google LLC |
| Status: |
Invalid (digital signature could be stolen or file could be patched) |
| %appdata% |
| %programfiles%\google |
| %programfiles%\google |
| %programfiles%\google |
Analysis
| Subsystem: |
Windows GUI |
| PE Type: |
pe |
| OS Bitness: |
64 |
| Image Base: |
0x0000000140000000 |
| Entry Address: |
0x000012fd |
| Name |
Size of data |
MD5 |
| .text |
30208 |
27d411291c7186939ec16f4388ed5295 |
| .data |
4584960 |
17b4c8acf19a23d669f84398fb64ded2 |
| .rdata |
11776 |
d5c45f8c00f43497b38cbd898138335a |
| .pdata |
1536 |
bd51e1d8aee2dfedeef4e44d20e83cf6 |
| .xdata |
1536 |
452e2f3723ff524964b776dc87031c89 |
| .bss |
0 |
d41d8cd98f00b204e9800998ecf8427e |
| .idata |
1536 |
7bd602d2dba6ef6c2f24307a589c9ba5 |
| .CRT |
512 |
a03b266e00e03e324913c7d640231993 |
| .tls |
512 |
bf619eac0cdf3f68d496ea9344137e8b |
| .rsrc |
12288 |
33d98541e9649926a0f11c0282703548 |
| .reloc |
512 |
63ed76ed09fc1ec93e09a9b92e20930d |