How to remove update64.exe
- File Details
- Overview
- Analysis
update64.exe
The module update64.exe has been detected as Trojan.CoinMiner
File Details
Product Name: |
|
Company Name: |
|
MD5: |
54cd8e1b80c421db507565a6234cfffe |
Size: |
588 KB |
First Published: |
2018-09-01 14:03:42 (6 years ago) |
Latest Published: |
2019-05-25 06:04:22 (5 years ago) |
Status: |
Trojan.CoinMiner (on last analysis) |
|
Analysis Date: |
2019-05-25 06:04:22 (5 years ago) |
Overview
%programfiles%\systema natives |
%programfiles%\systema natives |
%programfiles%\systema natives |
|
12.5% |
|
|
12.5% |
|
|
12.5% |
|
|
12.5% |
|
|
12.5% |
|
|
12.5% |
|
|
12.5% |
|
|
12.5% |
|
Windows 10 |
50.0% |
|
Windows 7 |
50.0% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x000435dd |
Name |
Size of data |
MD5 |
.text |
398848 |
b0de67d57d3f8da44f190bc455e27c5e |
.rdata |
112640 |
afec05ab0bb025dcc9332a3908a4a261 |
.data |
4096 |
be9b6d19c2be9d554f55c04c4dbcdab2 |
.rsrc |
55808 |
b28d36440efac5563768c296761960c1 |
.reloc |
22528 |
cd259a8182b95498b1116e53730e8dca |