How to remove $RQ5IXFQ.exe
- File Details
- Overview
- Analysis
$RQ5IXFQ.exe
The module $RQ5IXFQ.exe has been detected as Trojan.Agent
File Details
MD5: |
65b49b106ec0f6cf61e7dc04c0a7eb74 |
Size: |
1 MB |
First Published: |
2018-01-13 21:14:04 (6 years ago) |
Latest Published: |
2022-12-04 23:35:57 (a year ago) |
Status: |
Trojan.Agent (on last analysis) |
|
Analysis Date: |
2022-12-04 23:35:57 (a year ago) |
%temp% |
%sysdrive%\temp |
%programfiles% |
%profile%\downloads\compressed |
%commonappdata%\emco\malware destroyer 8\storage\quarantined threats\suspicious threats\desktop-k0p5ugh\suspicious threat 2156\file\localappdata\temp |
%desktop% |
%sysdrive%\docume~1\admini~1\locals~1\temp |
%profile%\onedrive\desktop |
%sysdrive%\$recycle.bin |
%profile%\downloads\vso_convertx_to_dvd_2_1_keygen (1) |
keygen-pr.exe |
keygen-pr pass 12345.exe |
$RQ5IXFQ.exe |
|
11.0% |
|
|
7.8% |
|
|
6.1% |
|
|
4.4% |
|
|
4.2% |
|
|
4.0% |
|
|
4.0% |
|
|
3.8% |
|
|
3.2% |
|
|
3.0% |
|
|
3.0% |
|
|
2.7% |
|
|
2.5% |
|
|
2.5% |
|
|
2.5% |
|
|
2.3% |
|
|
2.1% |
|
|
2.1% |
|
|
2.1% |
|
|
1.9% |
|
|
1.9% |
|
|
1.5% |
|
|
1.5% |
|
|
1.5% |
|
|
1.3% |
|
|
1.3% |
|
|
1.0% |
|
|
1.0% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.6% |
|
|
0.6% |
|
|
0.6% |
|
|
0.6% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
Windows 10 |
56.4% |
|
Windows 7 |
36.2% |
|
Windows 8.1 |
3.8% |
|
Windows XP |
2.2% |
|
Windows 8 |
0.7% |
|
Windows Vista |
0.4% |
|
Windows Server 2008 R2 |
0.2% |
|
Windows Server 2012 R2 |
0.2% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x0001d728 |
Name |
Size of data |
MD5 |
.text |
153088 |
22ced87f8cfbeec19f10ea768b9f5033 |
.rdata |
20480 |
9aea8072fe8459f1fb075382c5799ef0 |
.data |
5120 |
5aafebbc10957e661762e0e7fadc057b |
.rsrc |
17920 |
b14d0895410f411130e4509f77bb7b7e |