How to remove update.exe
update.exe
The module update.exe has been detected as Hijack.IE

File Details
Product Name: | 返钱宝宝升级程序 |
MD5: | 0ff3e153f197afaba61cfd7e53e63c8b |
Size: | 95 KB |
First Published: | 2017-07-27 12:09:31 (7 years ago) |
Latest Published: | 2018-10-30 08:14:02 (6 years ago) |
Status: | Hijack.IE (on last analysis) | |
Analysis Date: | 2018-10-30 08:14:02 (6 years ago) |
Overview
Signed By: | Shanghai Zheyue Financial Information Service Co.,Ltd. |
Status: | Valid |
Common Places:
%localappdata%\fanqianbao\2.0.1.10 |
%localappdata%\fanqianbao\1.0.1.74 |
%localappdata%\fanqianbao\1.0.1.55 |
%localappdata%\fanqianbao\1.0.1.46 |
%localappdata%\fanqianbao |
Geography:
88.2% | ||
11.8% |
OS Version:
Windows 10 | 64.7% | |
Windows 7 | 23.5% | |
Windows 8.1 | 11.8% |
Analysis
Subsystem: | Windows GUI |
PE Type: | pe |
OS Bitness: | 32 |
Image Base: | 0x00400000 |
Entry Address: | 0x00003bd2 |
PE Sections:
Name | Size of data | MD5 |
.text | 39424 | 257b389aa7bd5acca9cbb7f6aa9cd5e4 |
.rdata | 26112 | d184fd93254fe9c055f9c7005d2e5b62 |
.data | 4096 | 31103284796ef6a96b8b401f2b54b66a |
.rsrc | 11776 | 63b1482d02d5322c9779de142aad8c32 |
.reloc | 8192 | f2969f365538bed7f42bfc67eb993242 |
More information:
Download GridinSoft
Anti-Malware - Removal tool for update.exe
