How to remove $RRXEO7L.exe
- File Details
- Overview
- Analysis
$RRXEO7L.exe
The module $RRXEO7L.exe has been detected as Trojan.Agent
File Details
| Product Name: |
|
| MD5: |
f51a11475770c7303fc2f4db0120cc22 |
| Size: |
133 KB |
| First Published: |
2017-12-22 18:13:30 (7 years ago) |
| Latest Published: |
2021-01-01 10:36:22 (4 years ago) |
| Status: |
Trojan.Agent (on last analysis) |
|
| Analysis Date: |
2021-01-01 10:36:22 (4 years ago) |
| %commonappdata% |
| %startup% |
| %programfiles% |
| %sysdrive%\$recycle.bin |
| %sysdrive%\$recycle.bin |
| %sysdrive%\$recycle.bin |
| %commonappdata% |
| %sysdrive% |
| %sysdrive%\$recycle.bin |
| %sysdrive%\$recycle.bin |
Analysis
| Subsystem: |
Windows GUI |
| PE Type: |
pe |
| OS Bitness: |
32 |
| Image Base: |
0x00400000 |
| Entry Address: |
0x00013d0e |
| MVID: |
27db4ae6-ad3d-48c4-b5fd-8d25e85f204b |
| Typelib ID: |
a1e388f7-4c21-412b-ae1e-dceda12e2f3e |
| Name |
Size of data |
MD5 |
| .text |
73216 |
9365c0ce467ff6a60fa69db8a659e8e6 |
| .rsrc |
61952 |
574459bbf7f02d0df22d77b4fd0b2da5 |
| .reloc |
512 |
834c27ccabda7a97d1e1c27b586702ac |