How to remove $RKAE78B.exe
- File Details
- Overview
- Analysis
$RKAE78B.exe
The module $RKAE78B.exe has been detected as PUP.MailRu
File Details
| Product Name: |
|
| Company Name: |
|
| MD5: |
efd81d55503fcfd0fe1b65dd8362f333 |
| Size: |
26 MB |
| First Published: |
2018-05-23 14:05:09 (7 years ago) |
| Latest Published: |
2021-04-24 20:31:36 (4 years ago) |
| Status: |
PUP.MailRu (on last analysis) |
|
| Analysis Date: |
2021-04-24 20:31:36 (4 years ago) |
Overview
| %appdata%\icq |
| %appdata%\icq\updates |
| %sysdrive%\$recycle.bin |
| %sysdrive%\system volume information\_restore{9322ff0b-b4e0-41bd-a0e6-331cd7f07536} |
| %profile%\dmin\application data\icq |
| %profile%\dministrator\application data\icq |
| %appdata%\icq |
| %appdata%\icq |
| %appdata%\icq |
| %appdata%\icq |
| icq.exe |
| $RKAE78B.exe |
| A0210155.exe |
|
53.5% |
|
|
8.8% |
|
|
6.0% |
|
|
4.7% |
|
|
2.8% |
|
|
2.8% |
|
|
2.3% |
|
|
2.3% |
|
|
1.9% |
|
|
1.9% |
|
|
1.4% |
|
|
1.4% |
|
|
1.4% |
|
|
1.4% |
|
|
0.9% |
|
|
0.9% |
|
|
0.9% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
| Windows 10 |
61.0% |
|
| Windows 7 |
28.4% |
|
| Windows 8.1 |
7.8% |
|
| Windows XP |
1.8% |
|
| Windows Embedded Standard |
0.5% |
|
| Windows Server 2008 R2 |
0.5% |
|
Analysis
| Subsystem: |
Windows GUI |
| PE Type: |
pe |
| OS Bitness: |
32 |
| Image Base: |
0x00400000 |
| Entry Address: |
0x010ad9dc |
| Name |
Size of data |
MD5 |
| .text |
18844160 |
85f400651563d32c3207e54fb0483d83 |
| .rdata |
7454208 |
dfb8b93eddb5fdd18fd6ad635395e389 |
| .data |
270848 |
1dabd9c29c97407de0b118b0c96928eb |
| .rodata |
28672 |
69ae5ea5f29de3e867e7fa2e50b2b783 |
| .qtmetad |
1536 |
90bbd51953e48b326f0bbbe91f990e5d |
| _RDATA |
10752 |
922034d0ac58bb02cce0eb2e0379acab |
| .rsrc |
199680 |
7a34525bfc97bc4a201bd314dc549862 |
| .reloc |
651776 |
599ae4967bb6ceb2fba4600a1d9211bb |