How to remove $RECQ58M.exe
- File Details
- Overview
- Analysis
$RECQ58M.exe
The module $RECQ58M.exe has been detected as Adware.Toolbar
File Details
Product Name: |
|
Company Name: |
|
MD5: |
69114ed0796a10b73755c816f5e6b5e7 |
Size: |
7 MB |
First Published: |
2023-08-01 23:22:40 (2 years ago) |
Latest Published: |
2024-02-26 23:33:18 (a year ago) |
Status: |
Adware.Toolbar (on last analysis) |
|
Analysis Date: |
2024-02-26 23:33:18 (a year ago) |
Overview
Signed By: |
URSoft, Inc. |
Status: |
Invalid (digital signature could be stolen or file could be patched) |
%sysdrive%\$recycle.bin |
%sysdrive%\filehistory\20122\desktop-n28hpsj\data\c\users\20122 |
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x000b5eec |
Name |
Size of data |
MD5 |
.text |
735744 |
43af0a9476ca224d8e8461f1e22c94da |
.itext |
6144 |
185e04b9a1f554e31f7f848515dc890c |
.data |
14336 |
cab2107c933b696aa5cf0cc6c3fd3980 |
.bss |
0 |
d41d8cd98f00b204e9800998ecf8427e |
.idata |
4096 |
e7d1635e2624b124cfdce6c360ac21cd |
.didata |
512 |
8ced971d8a7705c98b173e255d8c9aa7 |
.edata |
512 |
8d4e1e508031afe235bf121c80fd7d5f |
.tls |
0 |
d41d8cd98f00b204e9800998ecf8427e |
.rdata |
512 |
8f2f090acd9622c88a6a852e72f94e96 |
.rsrc |
123904 |
93a2019b91e739cdd32ea291d92bdc1b |