How to remove osprovision.exe
- File Details
- Overview
- Analysis
osprovision.exe
The module osprovision.exe has been detected as Trojan.CoinMiner
File Details
Product Name: |
|
Company Name: |
|
MD5: |
d06063a16e89fcf580082b46154c7f71 |
Size: |
4 MB |
First Published: |
2018-06-08 15:07:27 (6 years ago) |
Latest Published: |
2018-06-12 03:01:45 (6 years ago) |
Status: |
Trojan.CoinMiner (on last analysis) |
|
Analysis Date: |
2018-06-12 03:01:45 (6 years ago) |
Overview
%programfiles%\caphyon\advanced installer 14.9 |
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x000db449 |
Name |
Size of data |
MD5 |
.text |
1200640 |
2c55b3165937f9158ad9400e58911a0f |
.rdata |
347648 |
7f208135fa97a70902c739670b0cb303 |
.data |
9216 |
42e37faccc0b1a1a4e06ea7b241c4fa8 |
.rsrc |
87040 |
fa55b9f8cb361e3cf17c551eb082f48a |
.reloc |
86528 |
844191152e905f62933c9f5e7cef82db |