How to remove funspace.update.process.exe
- File Details
- Overview
- Analysis
funspace.update.process.exe
The module funspace.update.process.exe has been detected as Trojan.LoadMoney
File Details
Product Name: |
|
Company Name: |
|
MD5: |
122beefccd64ca4734a299c66b2d7c77 |
Size: |
472 KB |
First Published: |
2017-07-12 11:02:40 (7 years ago) |
Latest Published: |
2020-07-27 00:19:17 (4 years ago) |
Status: |
Trojan.LoadMoney (on last analysis) |
|
Analysis Date: |
2020-07-27 00:19:17 (4 years ago) |
%appdata%\funspace\shadow\funspace.update |
%appdata%\funspace\vkmusicupd |
%appdata%\funspace\shadow |
%appdata%\funspace |
%appdata%\funspace |
%localappdata%\package cache\{c28b1f04-053c-417a-af2e-7b690e16ce17}v1.0.5353.18304 |
FunSpace.Update.Process.exe |
funspace.update.process.exe |
Windows 7 |
66.7% |
|
Windows 10 |
16.7% |
|
Windows 8.1 |
16.7% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x0007676e |
MVID: |
04f8c501-3f8a-474b-b981-988ce526304b |
Typelib ID: |
f1e0f153-99cc-4a0c-b450-17b1d2428417 |
Name |
Size of data |
MD5 |
.text |
477184 |
62ac5bea5b06eeecb4897ce48b1f3485 |
.rsrc |
2048 |
687868061052d136b92bcf3f898ce0c2 |
.reloc |
512 |
0b5a9dac0004a08988dd94c1e21a8993 |