How to remove winhost.exe
- File Details
- Overview
- Analysis
winhost.exe
The module winhost.exe has been detected as Trojan.Agent
File Details
| Product Name: |
|
| Company Name: |
|
| MD5: |
aac9f116adef3883d05f0fdf76d257e3 |
| Size: |
2 MB |
| First Published: |
2020-06-26 16:50:48 (5 years ago) |
| Latest Published: |
2021-10-13 20:50:35 (4 years ago) |
| Status: |
Trojan.Agent (on last analysis) |
|
| Analysis Date: |
2021-10-13 20:50:35 (4 years ago) |
Overview
| %localappdata% |
| %localappdata% |
| %localappdata% |
| %localappdata% |
| %localappdata% |
| %localappdata% |
| %localappdata% |
| %localappdata% |
| %localappdata% |
|
33.3% |
|
|
33.3% |
|
|
11.1% |
|
|
11.1% |
|
|
11.1% |
|
| Windows 10 |
66.7% |
|
| Windows 7 |
33.3% |
|
Analysis
| Subsystem: |
Windows GUI |
| PE Type: |
pe |
| OS Bitness: |
32 |
| Image Base: |
0x00400000 |
| Entry Address: |
0x0015d500 |
| Name |
Size of data |
MD5 |
| .text |
1920000 |
336ee985f5e4c2ea10a29f0d67f4282b |
| .rdata |
165376 |
34908bff8d3f7056ab9f72a07b95739e |
| .data |
30720 |
26138935bd20d25f16b7aa7c75732e00 |
| .rsrc |
83456 |
fe18f8d728693035302b4386365f72cc |
| .reloc |
70144 |
d2e96559771c051f5eba764c87751f47 |