How to remove images.scr
images.scr
The module images.scr has been detected as Trojan.CoinMiner
File Details
Product Name: | Images folder (x86-x64) |
Company Name: | |
MD5: | 4b2437b6bb7dc37b4a83c14e77532e0b |
Size: | 4 MB |
First Published: | 2017-06-20 18:03:05 (6 years ago) |
Latest Published: | 2021-03-25 21:30:24 (3 years ago) |
Status: | Trojan.CoinMiner (on last analysis) | |
Analysis Date: | 2021-03-25 21:30:24 (3 years ago) |
Common Places:
%appdata%\images |
%appdata% |
%sysdrive% |
%sysdrive%\$recycle.bin |
%profile% |
%appdata% |
%temp% |
%temp% |
%appdata% |
%appdata% |
File Names:
image.exe |
images.scr |
$R4N3ZG8.scr |
$R07MN8L.scr |
$R82SZ53.scr |
$R2YRLX5.scr |
$R45OOJO.scr |
$RP9B8NV.scr |
$R9HMGL1.scr |
$R94ND4L.scr |
$R45SDLS.scr |
$RVWRJIU.scr |
$RWJ368Q.scr |
$RR9U1WV.scr |
$RY7E74T.scr |
Geography:
99.3% | ||
0.5% | ||
0.2% |
OS Version:
Windows 7 | 86.1% | |
Windows 10 | 9.6% | |
Windows 8.1 | 3.8% | |
Windows 8 | 0.5% |
Analysis
Subsystem: | Windows GUI |
PE Type: | pe |
OS Bitness: | 32 |
Image Base: | 0x00400000 |
Entry Address: | 0x000030fa |
PE Sections:
Name | Size of data | MD5 |
.text | 24064 | 856b32eb77dfd6fb67f21d6543272da5 |
.rdata | 5120 | dc77f8a1e6985a4361c55642680ddb4f |
.data | 1024 | 7922d4ce117d7d5b3ac2cffe4b0b5e4f |
.ndata | 0 | 00000000000000000000000000000000 |
.rsrc | 56320 | e11f7d72f9917a6708750856899916bf |
More information:
Download GridinSoft
Anti-Malware - Removal tool for images.scr