How to remove $R2ASHFT.exe
- File Details
- Overview
- Analysis
$R2ASHFT.exe
The module $R2ASHFT.exe has been detected as General Threat
File Details
Product Name: |
|
Company Name: |
|
MD5: |
6a556756e039cffff79b971bed0632ed |
Size: |
4 MB |
First Published: |
2017-06-25 07:02:33 (7 years ago) |
Latest Published: |
2019-05-31 12:10:00 (5 years ago) |
Status: |
General Threat (on last analysis) |
|
Analysis Date: |
2019-05-31 12:10:00 (5 years ago) |
%sysdrive%\$recycle.bin |
%sysdrive%\soft\office |
%sysdrive%\thuong\soft\dictionary |
Fonts VNI.exe |
$R2ASHFT.exe |
Windows 10 |
75.0% |
|
Windows XP |
25.0% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x0004a042 |
Name |
Size of data |
MD5 |
|
42496 |
721ce33593c4d5e6f2f278b1e178eebf |
|
0 |
00000000000000000000000000000000 |
|
0 |
00000000000000000000000000000000 |
|
0 |
00000000000000000000000000000000 |
|
512 |
e7d0f785cb8381e84e80edd62306ff23 |
|
0 |
00000000000000000000000000000000 |
|
16448 |
507e76fd29c08783e54b76be50632f30 |
.petite |
1536 |
0a3972810230d0b561b36793d7490f75 |