How to remove systems.exe
- File Details
- Overview
- Analysis
systems.exe
The module systems.exe has been detected as Trojan.CoinMiner
File Details
Product Name: |
|
Company Name: |
|
MD5: |
1299d4af8de593678175e02565e79593 |
Size: |
4 MB |
First Published: |
2020-03-20 12:32:38 (5 years ago) |
Latest Published: |
2021-02-09 04:30:51 (4 years ago) |
Status: |
Trojan.CoinMiner (on last analysis) |
|
Analysis Date: |
2021-02-09 04:30:51 (4 years ago) |
%windir%\debug |
%appdata% |
%windir%\debug |
%windir%\debug |
Windows Server 2008 R2 |
66.7% |
|
Windows 8.1 |
33.3% |
|
Analysis
Subsystem: |
Windows CUI |
PE Type: |
pe |
OS Bitness: |
64 |
Image Base: |
0x0000000140000000 |
Entry Address: |
0x002015a4 |
Name |
Size of data |
MD5 |
.text |
3104256 |
74b3ef74bfa0d294d4e1e274bdda0399 |
.rdata |
940032 |
092db1feda2b8f1680772475f1634ed9 |
.data |
281088 |
929917d41ad9ef06b1eadcb0fe5b6b3c |
.pdata |
129536 |
404cf5c4409a31bca4ca0e95957a9913 |
_RANDOMX |
1536 |
d9024f8fd040694ff6e16174a3240aca |
_TEXT_CN |
6656 |
6a7f77e47f77f65bef85036ae5a71106 |
_TEXT_CN |
4608 |
409bf3f918f2402291cb56c2e9354b47 |
.rsrc |
23040 |
2a75eba6941ed965d1206bdb414bd485 |
.reloc |
33280 |
04615ac2712b20bc5eb3f2e18b42ab25 |