How to remove $R6NBO8X.exe
- File Details
- Overview
- Analysis
$R6NBO8X.exe
The module $R6NBO8X.exe has been detected as PUP.Gen
File Details
Product Name: |
|
Company Name: |
|
MD5: |
f88d710429fdc3f70e513fe10b4d30ec |
Size: |
4 MB |
First Published: |
2017-09-22 18:08:44 (7 years ago) |
Latest Published: |
2018-03-07 20:04:28 (6 years ago) |
Status: |
PUP.Gen (on last analysis) |
|
Analysis Date: |
2018-03-07 20:04:28 (6 years ago) |
Overview
%programfiles%\wipersoft |
%sysdrive%\adwcleaner\quarantine\1xvpfvjcrg |
%sysdrive%\$recycle.bin\s-1-5-21-936599910-2383192686-2678254505-1001 |
%sysdrive%\adwcleaner\quarantine\fraqbc8wsa |
%sysdrive%\adwcleaner\quarantine\x3cf3ednhm |
%sysdrive%\$recycle.bin\s-1-5-21-2275429643-1357250638-3055656149-1001\$rym2l08 |
%programfiles% |
WiperSoft.exe |
$R6NBO8X.exe |
|
10.5% |
|
|
8.0% |
|
|
8.0% |
|
|
8.0% |
|
|
6.8% |
|
|
6.8% |
|
|
6.2% |
|
|
4.3% |
|
|
3.7% |
|
|
3.7% |
|
|
3.7% |
|
|
2.5% |
|
|
2.5% |
|
|
1.9% |
|
|
1.9% |
|
|
1.9% |
|
|
1.9% |
|
|
1.2% |
|
|
1.2% |
|
|
1.2% |
|
|
1.2% |
|
|
1.2% |
|
|
1.2% |
|
|
1.2% |
|
|
1.2% |
|
|
0.6% |
|
|
0.6% |
|
|
0.6% |
|
|
0.6% |
|
|
0.6% |
|
|
0.6% |
|
|
0.6% |
|
|
0.6% |
|
|
0.6% |
|
|
0.6% |
|
|
0.6% |
|
|
0.6% |
|
|
0.6% |
|
Windows 10 |
65.2% |
|
Windows 7 |
21.3% |
|
Windows 8.1 |
11.0% |
|
Windows Server 2012 R2 |
1.2% |
|
Windows Embedded 8.1 |
0.6% |
|
Windows Server 2008 R2 |
0.6% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
64 |
Image Base: |
0x0000000140000000 |
Entry Address: |
0x002d5914 |
Name |
Size of data |
MD5 |
.text |
3392512 |
65c9ceaa3390121462717c7227ef9390 |
.rdata |
991744 |
c76c827cddaddc9a0f4e519090092420 |
.data |
115200 |
c6e260fff4653e4917d8494d45adf8b9 |
.pdata |
156672 |
97b2974ad4344b4bd1faa1112d5f6f71 |
.tls |
512 |
bf619eac0cdf3f68d496ea9344137e8b |
ATL |
512 |
bf619eac0cdf3f68d496ea9344137e8b |
text |
7680 |
93d474f9fc0540e6afd1685236f27a41 |
data |
25600 |
77ecc2959150016af71ff7d0dce83dc7 |
.rsrc |
188928 |
9708c728ee2b890355c3d69f2df519a5 |
.reloc |
28672 |
f54258ab9c86ddd001055a6fbb25c8b0 |