How to remove $RAVJSZ0.exe
- File Details
- Overview
- Analysis
$RAVJSZ0.exe
The module $RAVJSZ0.exe has been detected as Suspicious Object
File Details
MD5: |
a356b6b6f686298df70c379a6b52b569 |
Size: |
808 KB |
First Published: |
2017-12-19 19:04:42 (7 years ago) |
Latest Published: |
2020-10-02 17:21:59 (4 years ago) |
Status: |
Suspicious Object (on last analysis) |
|
Analysis Date: |
2020-10-02 17:21:59 (4 years ago) |
Overview
%commonappdata%\ttop\geogebra_6 |
%localappdata%\geogebra_6 |
%sysdrive%\$recycle.bin |
%localappdata%\squirreltemp\tempb\lib |
%profile%\downloads\compressed\jaore\appdata\local\geogebra_6 |
%localappdata%\geogebra_6\packages\geogebra_6.0-6.0.451-full.nupkg\lib |
%localappdata%\squirreltemp\tempd\lib |
%localappdata%\geogebra_6\packages\geogebra_6.0-6.0.496-full.nupkg\lib |
%profile% |
disablekeys.exe |
$RAVJSZ0.exe |
$REC34GD.exe |
|
14.5% |
|
|
10.7% |
|
|
6.9% |
|
|
6.9% |
|
|
6.1% |
|
|
4.6% |
|
|
3.8% |
|
|
3.8% |
|
|
3.8% |
|
|
3.1% |
|
|
3.1% |
|
|
3.1% |
|
|
2.3% |
|
|
2.3% |
|
|
2.3% |
|
|
2.3% |
|
|
2.3% |
|
|
1.5% |
|
|
1.5% |
|
|
1.5% |
|
|
1.5% |
|
|
1.5% |
|
|
1.5% |
|
|
1.5% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
Windows 10 |
72.5% |
|
Windows 7 |
16.0% |
|
Windows 8.1 |
11.5% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x000902d3 |
Name |
Size of data |
MD5 |
.text |
642560 |
ed222528c0af141da47ff8a47c345c52 |
.rdata |
144384 |
25f8d7882fc2a14d37f5ce858ebb9321 |
.data |
12800 |
ace5eafa538405645cda58c972af5d6c |
.rsrc |
24064 |
14366335886db2525f1568dd7c847e5e |