在线病毒检测器 | v.1.0.204.174 |
数据库版本: | 2025-01-13 02:00:38 |
CoinMiner是一种利用受害者的计算机资源(主要是CPU和RAM)进行加密货币挖掘(例如Monero或Zcash)的恶意软件。此恶意软件通过将开源挖掘工具集成到系统的启动例程中来建立持久性,而不需要用户的同意。高级的加密货币挖掘程序通常采用定时器配置或CPU使用限制等技术,以悄悄运行并避免检测。
File | Win 10 Tweaker.exe |
已检查 | 2025-01-13 01:04:09 |
MD5 | e21d817cc0a116d1930f4a77d6877010 |
SHA1 | c11c41274ca197b744dc900d753662d451a58baa |
SHA256 | 8cfcd9eba58d7488f34fd19c00e5a7ef6041f8e6c2024e420e5f5b8b34667a9c |
SHA512 | ca38f1db73063e7bf7574096a351a9ee9802ba88ef4c42c1439022c443c9fb4be224242a6ea19bd3fc3b17554a3c6baec7dcf7ce79971178a0ce1a15ba4e3f47 |
Imphash | f34d5f2d4577ed6d9ceec516c1f5a744 |
File Size | 1814528 bytes |
Gridinsoft能够识别并消除Trojan.Win32.CoinMiner.ca,无需进一步的用户干预。
Translation | 0x0000 0x04b0 |
Comments | Win 10 Tweaker |
CompanyName | XpucT |
FileDescription | Win 10 Tweaker |
FileVersion | 20.3 |
InternalName | Win 10 Tweaker.exe |
LegalCopyright | Copyright © XpucT |
LegalTrademarks | XpucT |
OriginalFilename | Win 10 Tweaker.exe |
ProductName | Win 10 Tweaker |
ProductVersion | 20.3 |
Assembly Version | 20.3.0.0 |
c58619a4fdb9140efb2b327aca5d1765 4934aca9266f60178688b911cf75be88 b2b196901fd8cbae |
|
Image Base: | 0x00400000 |
Entry Point: | 0x005be08a |
Compilation: | 2024-08-23 02:20:19 |
Checksum: | 0x00000000 (Actual: 0x001bd3f8) |
OS Version: | 4.0 |
PEiD: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
Sign: | No valid SignedData structure was found. |
Sections: | 5 |
Imports: | mscoree, |
Exports: | 0 |
Resources: | 7 |
名称 | 虚拟地址 | 虚拟大小 | 原始大小 | MD5 | 熵 |
---|---|---|---|---|---|
C!3QbU | 0x00002000 | 0x001a7d50 | 0x001a7e00 | d5c5117992cf7f0b035e31a022df6b0d | 8.00 |
.text | 0x001aa000 | 0x0000d888 | 0x0000da00 | f3da37aba01fa6e375034e99f3cde240 | 5.22 |
.rsrc | 0x001b8000 | 0x00004ecc | 0x00005000 | a803d397fdb99d51fb7f4810181421bf | 4.16 |
0x001be000 | 0x00000090 | 0x00000200 | ebf7dd32287050849fde63d5933bb254 | 2.52 | |
.reloc | 0x001c0000 | 0x0000000c | 0x00000200 | 0c390f2e055d14f39951340b4c48ee03 | 0.10 |