How to remove update.exe
update.exe
The module update.exe has been detected as Trojan.Agent
File Details
Product Name: | WPS Office |
Company Name: | Zhuhai Kingsoft Office Software Co.,Ltd |
MD5: | f1070fb75810c9a8806a7d7604a5a05c |
Size: | 1 MB |
First Published: | 2017-06-13 11:08:34 (7 years ago) |
Latest Published: | 2017-09-29 17:06:15 (7 years ago) |
Status: | Trojan.Agent (on last analysis) | |
Analysis Date: | 2017-09-29 17:06:15 (7 years ago) |
Overview
Signed By: | Zhuhai Kingsoft Office Software Co.,Ltd |
Status: | Valid |
Common Places:
%localappdata%\kingsoft\power word 2016\2016.3.3.0306 |
%localappdata%\kingsoft\power word 2016\2016.3.3.0316 |
%appdata%\kingsoft\powerword\update\down |
%temp%\power word\~2e41ab77 |
%temp%\power word\~3335aefa |
Geography:
65.4% | ||
13.2% | ||
5.9% | ||
4.4% | ||
2.9% | ||
2.9% | ||
1.5% | ||
1.5% | ||
1.5% | ||
0.7% |
OS Version:
Windows 7 | 74.3% | |
Windows 10 | 24.3% | |
Windows 8.1 | 1.5% |
Analysis
Subsystem: | Windows GUI |
PE Type: | pe |
OS Bitness: | 32 |
Image Base: | 0x00400000 |
Entry Address: | 0x000945cc |
PE Sections:
Name | Size of data | MD5 |
.text | 772608 | ff84ba8a43182f7ebf6ba4ad797b4b30 |
.rdata | 231424 | f8e354937a7a0ecd52adb26135578bb4 |
.data | 20992 | f58664f1859364410012cf9f3d0a83c1 |
.rsrc | 81920 | 41b935e0910a45b898e2bef72bdef06c |
More information:
Download GridinSoft
Anti-Malware - Removal tool for update.exe