How to remove winhost.exe
- File Details
- Overview
- Analysis
winhost.exe
The module winhost.exe has been detected as PUP.FlySvr
File Details
| Product Name: |
|
| Company Name: |
|
| MD5: |
ac5c40539bfa1fbd1ae58b2dcd19698b |
| Size: |
2 MB |
| First Published: |
2020-05-30 15:32:49 (5 years ago) |
| Latest Published: |
2023-01-12 23:18:14 (2 years ago) |
| Status: |
PUP.FlySvr (on last analysis) |
|
| Analysis Date: |
2023-01-12 23:18:14 (2 years ago) |
Overview
| %localappdata% |
| %localappdata% |
| %localappdata% |
| %localappdata% |
| %localappdata% |
| %localappdata% |
| %sysdrive%\$recycle.bin\s-1-5-18\$rf4ier9.old\users\abdou\appdata\local |
| Windows 7 |
57.1% |
|
| Windows 10 |
42.9% |
|
Analysis
| Subsystem: |
Windows GUI |
| PE Type: |
pe |
| OS Bitness: |
32 |
| Image Base: |
0x00400000 |
| Entry Address: |
0x0015c2ad |
| Name |
Size of data |
MD5 |
| .text |
1914880 |
4dde946b2d65d061937be4f5cadbe033 |
| .rdata |
164864 |
f81d634f82de90a137993585456dc85f |
| .data |
30720 |
42e8f809535532d4265f50c61e0c44aa |
| .rsrc |
83456 |
35d957fba97ab92e387777e3e696fad1 |
| .reloc |
69632 |
a40f91027ab031a75831bd3399b8b8ef |