How to remove $RJAVAZE.exe
- File Details
- Overview
- Analysis
$RJAVAZE.exe
The module $RJAVAZE.exe has been detected as Adware.Agent
File Details
MD5: |
6adb4f8219a16f475ec87f8374cb3cdf |
Size: |
1 MB |
First Published: |
2017-05-24 13:08:42 (6 years ago) |
Latest Published: |
2019-09-13 13:33:47 (4 years ago) |
Status: |
Adware.Agent (on last analysis) |
|
Analysis Date: |
2019-09-13 13:33:47 (4 years ago) |
%temp%\00008939 |
%temp%\00031107 |
%temp%\00003275 |
%temp%\00006500 |
%temp%\00010032 |
%temp%\00000223 |
%temp%\00029084 |
%temp%\00000374 |
%temp%\00027192 |
%temp%\00004603 |
msiql.exe |
$RJAVAZE.exe |
msiql.exe.dav |
msiql.exe |
unp93451807.tmp |
$RZ53Y2W.exe |
MSIQL.EXE |
$RIO3XGJ.exe |
msiql.exe.q_Quarantine_1145A01F_q |
msiql.exe.dat |
msiql.exe.q_Quarantine_1894A01F_q |
|
35.6% |
|
|
12.8% |
|
|
8.2% |
|
|
5.4% |
|
|
4.1% |
|
|
3.7% |
|
|
2.4% |
|
|
1.5% |
|
|
1.5% |
|
|
1.4% |
|
|
1.3% |
|
|
1.3% |
|
|
1.2% |
|
|
1.1% |
|
|
1.1% |
|
|
1.0% |
|
|
1.0% |
|
|
0.9% |
|
|
0.7% |
|
|
0.7% |
|
|
0.6% |
|
|
0.5% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
Windows 7 |
54.0% |
|
Windows 10 |
36.6% |
|
Windows 8.1 |
7.7% |
|
Windows 8 |
1.4% |
|
Windows Vista |
0.2% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x0008eb1a |
Name |
Size of data |
MD5 |
.text |
1627136 |
027c390f29c242ed3dc2a7e9c659b2ba |
.rdata |
316928 |
512b27821d65013b55f54f4f706119f4 |
.data |
36864 |
cb363509f101c4f8afc637b91a8f9967 |
.rsrc |
11264 |
f29122e725a66d56960dacd16d5c8e73 |
.reloc |
79360 |
fb4842b0db564332f844d4ca4a0bd6b1 |