How to remove 18671D40-0F43-44A7-93FE-5BEBA5E796A1.exe

18671D40-0F43-44A7-93FE-5BEBA5E796A1.exe

The module 18671D40-0F43-44A7-93FE-5BEBA5E796A1.exe has been detected as Adware.Crossrider

18671D40-0F43-44A7-93FE-5BEBA5E796A1.exe
MD5: 7c2ff5e04bc4aa19536bcfd78ca383e4
Size: 5 MB
First Published: 2017-05-28 11:09:16 (7 years ago)
Latest Published: 2019-10-11 18:55:36 (5 years ago)
Status: Adware.Crossrider (on last analysis)
Analysis Date: 2019-10-11 18:55:36 (5 years ago)
%appdata%\pushcontrol
%profile%\dmin\application data\pushcontrol
%sysdrive%\docume~1\admin\locals~1\temp\18671d40-0f43-44a7-93fe-5beba5e796a1
%temp%\3d8cd657-456f-4d72-9820-ce260aa95b21
%appdata%
%sysdrive%\!!!!!\users2\лена\appdata\roaming
%profile%\dmin\application data
%temp%
%profile%\rtem\application data
%sysdrive%\windows.old\users\user\appdata\roaming
PushControl.exe
18671D40-0F43-44A7-93FE-5BEBA5E796A1.exe
3D8CD657-456F-4D72-9820-CE260AA95B21.exe
C7D3D4D7-C34F-4C5C-8428-F4D45E78552C.exe
97D9E5AA-4EC4-4BFD-A7C7-0989F706BFA3.exe
02BC819D-BE70-4A94-BC78-03BEE79951BE.exe
61.9%
38.1%
Windows 7 45.2%
Windows 10 26.2%
Windows 8.1 19.0%
Windows XP 9.5%
Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x0036a6a4

PE Sections:

Name Size of data MD5
.text 3567616 b97318159bbcbab2581cc1faf6a27f48
.itext 10240 d3d5f6dc20237897aa7ab45081d75680
.data 51712 68f74a2b829f2c3c6f98043ce4bfed6d
.bss 0 00000000000000000000000000000000
.idata 15872 b6506e13bf10b90f58d5983dc67711aa
.didata 3072 03525c15240723f99439d12e9903853b
.edata 512 93c51cf1a60d32b8d2c65fd63375332c
.tls 0 00000000000000000000000000000000
.rdata 512 00ecdc720da50f5974de355fc101275a
.reloc 324096 cb8f822171514b7ba06175fb5a23e5da
.rsrc 306688 e564ebc911ec4b3cbef30d0e48456623

More information:

Download GridinSoft Anti-Malware - Removal tool for 18671D40-0F43-44A7-93FE-5BEBA5E796A1.exe