How to remove $ROCNSNE.exe
- File Details
- Overview
- Analysis
$ROCNSNE.exe
The module $ROCNSNE.exe has been detected as Rogue.Gen
File Details
MD5: |
dc9ba6b0cfdc80377e5fc34e98cda1bf |
Size: |
1017 KB |
First Published: |
2017-06-01 02:15:38 (7 years ago) |
Latest Published: |
2018-08-09 16:08:37 (6 years ago) |
Status: |
Rogue.Gen (on last analysis) |
|
Analysis Date: |
2018-08-09 16:08:37 (6 years ago) |
Overview
%localappdata%\temp |
%desktop%\千千靜聽 5.9.6 繁體中文免安裝版 |
%temp% |
%sysdrive%\downloads\千千靜聽v6.0繁體中文.exe |
%desktop%\備份\downloads003\千千靜聽v6.0繁體中文.exe |
%desktop%\桌面\應用程式 |
%desktop%\應用程式 |
%sysdrive%\system volume information\_restore{94b5c5d0-e4f9-434e-9263-52a59a4353b9}\rp84\a0014814.exe |
%sysdrive%\$recycle.bin |
%sysdrive%\l\downloads\ttplayer_portable_6.0.0 |
BaiduBarSilent.exe |
$ROCNSNE.exe |
|
80.0% |
|
|
16.7% |
|
|
1.1% |
|
|
1.1% |
|
|
1.1% |
|
Windows 7 |
72.2% |
|
Windows 10 |
26.7% |
|
Windows 8.1 |
1.1% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x0000323c |
Name |
Size of data |
MD5 |
.text |
23552 |
0bc2ffd32265a08d72b795b18265828d |
.rdata |
4608 |
f179218a059068529bdb4637ef5fa28e |
.data |
1024 |
975304d6dd6c4a4f076b15511e2bbbc0 |
.ndata |
0 |
00000000000000000000000000000000 |
.rsrc |
25088 |
ec65c0e087d7ddcd095c8010fe433dbf |