How to remove $REDYHS3.sys
- File Details
- Overview
- Analysis
$REDYHS3.sys
The module $REDYHS3.sys has been detected as PUP.MailRu
File Details
Product Name: |
|
Company Name: |
|
MD5: |
fb098256ea064803093d9b1a2f6d06ac |
Size: |
9 MB |
First Published: |
2018-10-05 20:08:24 (6 years ago) |
Latest Published: |
2023-06-24 23:12:53 (2 years ago) |
Status: |
PUP.MailRu (on last analysis) |
|
Analysis Date: |
2023-06-24 23:12:53 (2 years ago) |
Overview
%system% |
%sysdrive%\$recycle.bin |
%system% |
%system% |
%system% |
%system% |
%system% |
%system% |
%system% |
%system% |
mracdrv.sys |
$REDYHS3.sys |
$RAA79FM.sys |
$RNBOJ2L.sys |
Russia |
58.9% |
|
Ukraine |
6.6% |
|
Thailand |
3.0% |
|
United States |
2.5% |
|
Kazakhstan |
2.3% |
|
Germany |
2.3% |
|
Poland |
2.0% |
|
Belarus |
2.0% |
|
France |
1.5% |
|
Vietnam |
1.0% |
|
India |
1.0% |
|
Taiwan |
0.8% |
|
Italy |
0.8% |
|
Czech Republic |
0.8% |
|
Japan |
0.8% |
|
Mexico |
0.8% |
|
Philippines |
0.8% |
|
Serbia |
0.8% |
|
Belgium |
0.8% |
|
Chile |
0.8% |
|
South Korea |
0.5% |
|
Romania |
0.5% |
|
Iraq |
0.5% |
|
Israel |
0.5% |
|
Azerbaijan |
0.5% |
|
Hong Kong |
0.5% |
|
South Africa |
0.5% |
|
Singapore |
0.3% |
|
Armenia |
0.3% |
|
Colombia |
0.3% |
|
Moldova |
0.3% |
|
Croatia |
0.3% |
|
Libya |
0.3% |
|
Trinidad and Tobago |
0.3% |
|
Estonia |
0.3% |
|
Spain |
0.3% |
|
Nepal |
0.3% |
|
United Kingdom |
0.3% |
|
Sweden |
0.3% |
|
Pakistan |
0.3% |
|
Bosnia and Herzegovina |
0.3% |
|
Argentina |
0.3% |
|
Lithuania |
0.3% |
|
Turkey |
0.3% |
|
Peru |
0.3% |
|
Australia |
0.3% |
|
Netherlands |
0.3% |
|
Ecuador |
0.3% |
|
Indonesia |
0.3% |
|
Venezuela |
0.3% |
|
Honduras |
0.3% |
|
Greece |
0.3% |
|
Windows 10 |
67.5% |
|
Windows 7 |
24.4% |
|
Windows 8.1 |
7.8% |
|
Windows Embedded 8.1 |
0.3% |
|
Analysis
Subsystem: |
Native |
PE Type: |
pe |
OS Bitness: |
64 |
Image Base: |
0x0000000140000000 |
Entry Address: |
0x008a595e |
Name |
Size of data |
MD5 |
.text |
0 |
00000000000000000000000000000000 |
PFCDENP |
0 |
00000000000000000000000000000000 |
PCDENP |
0 |
00000000000000000000000000000000 |
.rdata |
0 |
00000000000000000000000000000000 |
.data |
0 |
00000000000000000000000000000000 |
.pdata |
0 |
00000000000000000000000000000000 |
.gfids |
0 |
00000000000000000000000000000000 |
INIT |
0 |
00000000000000000000000000000000 |
.vmp0 |
0 |
00000000000000000000000000000000 |
.vmp1 |
512 |
387d3cec6641bcedbf49389f4d198e83 |
.vmp2 |
10170880 |
2b3a1f9ca8ea98c2e954f25604f86e67 |
.reloc |
512 |
c2c7ff237634b1ec57cf2f400bd3a9d2 |
.rsrc |
1024 |
4b88d0a4f76ac73fb464c5a5f2ed814b |