How to remove windefend.exe
- File Details
- Overview
- Analysis
windefend.exe
The module windefend.exe has been detected as Risk.CoinMiner
File Details
Product Name: |
|
Company Name: |
|
MD5: |
b3f811eecc1d809a1a1fcaa282c1a800 |
Size: |
4 MB |
First Published: |
2018-07-16 14:11:19 (6 years ago) |
Latest Published: |
2018-07-16 14:13:28 (6 years ago) |
Status: |
Risk.CoinMiner (on last analysis) |
|
Analysis Date: |
2018-07-16 14:13:28 (6 years ago) |
%commondir%\microsoft\windows |
Analysis
Subsystem: |
Windows CUI |
PE Type: |
pe |
OS Bitness: |
64 |
Image Base: |
0x0000000140000000 |
Entry Address: |
0x0008d7d0 |
Name |
Size of data |
MD5 |
.text |
619008 |
007d0f3f33530fc5e3b2cba27388eb5e |
.rdata |
130048 |
3bc545d36c606e69e229ba222aebaba3 |
.data |
31744 |
789aa5d8cb58ab9bd8682e6c51bde0a9 |
.pdata |
20480 |
daa100df6e6711906b61c9ab5aa16032 |
.gfids |
512 |
5a837ae8b830099ba099e44178ca3a68 |
.tls |
512 |
1f354d76203061bfdd5a53dae48d5435 |
.rsrc |
26624 |
959d0e4eb734d0e59dab166ad1021782 |
.reloc |
1536 |
174bef746a10bd861cbe20c810ba0f59 |
.enigma1 |
3207168 |
8c26a62e6c94ae5d017676b5db72ebfa |
.enigma2 |
643072 |
eb20c1925cae1a5139cafc4e55529a50 |