How to remove $ROG0KVA.exe
- File Details
- Overview
- Analysis
$ROG0KVA.exe
The module $ROG0KVA.exe has been detected as Adware.ELEX
File Details
MD5: |
8cd38c184be2237a58717aa19ab02817 |
Size: |
112 KB |
First Published: |
2017-05-21 05:04:30 (7 years ago) |
Latest Published: |
2020-12-14 23:07:23 (3 years ago) |
Status: |
Adware.ELEX (on last analysis) |
|
Analysis Date: |
2020-12-14 23:07:23 (3 years ago) |
%localappdata%\clean |
%programfiles%\58e62344_cacayima\pack\2 |
%windir%\temp\hp2db6.tmp |
%windir%\temp\hpb7e7.tmp |
%temp%\hp3ae8.tmp |
%windir%\temp\tmpe0d5.tmp |
%windir%\temp\hp5ab7.tmp |
%temp%\hp3998.tmp |
%windir%\temp\hpdde2.tmp |
%temp%\hp30f0.tmp |
Kyubey.exe |
$ROG0KVA.exe |
Kyubey.exe.quarantined |
Kyubey.VIR |
|
40.4% |
|
|
12.5% |
|
|
6.8% |
|
|
6.4% |
|
|
5.7% |
|
|
3.4% |
|
|
3.4% |
|
|
2.6% |
|
|
2.3% |
|
|
2.3% |
|
|
1.1% |
|
|
1.1% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
Windows 7 |
74.3% |
|
Windows 10 |
12.3% |
|
Windows 8.1 |
5.9% |
|
Windows 8 |
4.8% |
|
Windows XP |
2.2% |
|
Windows Server 2012 R2 |
0.4% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x0000618a |
Name |
Size of data |
MD5 |
.text |
77824 |
bec10b8838cf6fe73de848e8f6c23fc5 |
.rdata |
30208 |
5266d0696fa7d55d2479e1832bfffa24 |
.data |
5120 |
6461ebc8555a7707ceebffafa662d011 |
.rsrc |
512 |
b673e4190face1157da6fed45aa68103 |