How to remove 18671D40-0F43-44A7-93FE-5BEBA5E796A1.exe
- File Details
- Overview
- Analysis
18671D40-0F43-44A7-93FE-5BEBA5E796A1.exe
The module 18671D40-0F43-44A7-93FE-5BEBA5E796A1.exe has been detected as Adware.Crossrider
File Details
MD5: |
7c2ff5e04bc4aa19536bcfd78ca383e4 |
Size: |
5 MB |
First Published: |
2017-05-28 11:09:16 (7 years ago) |
Latest Published: |
2019-10-11 18:55:36 (5 years ago) |
Status: |
Adware.Crossrider (on last analysis) |
|
Analysis Date: |
2019-10-11 18:55:36 (5 years ago) |
%appdata%\pushcontrol |
%profile%\dmin\application data\pushcontrol |
%sysdrive%\docume~1\admin\locals~1\temp\18671d40-0f43-44a7-93fe-5beba5e796a1 |
%temp%\3d8cd657-456f-4d72-9820-ce260aa95b21 |
%appdata% |
%sysdrive%\!!!!!\users2\лена\appdata\roaming |
%profile%\dmin\application data |
%temp% |
%profile%\rtem\application data |
%sysdrive%\windows.old\users\user\appdata\roaming |
PushControl.exe |
18671D40-0F43-44A7-93FE-5BEBA5E796A1.exe |
3D8CD657-456F-4D72-9820-CE260AA95B21.exe |
C7D3D4D7-C34F-4C5C-8428-F4D45E78552C.exe |
97D9E5AA-4EC4-4BFD-A7C7-0989F706BFA3.exe |
02BC819D-BE70-4A94-BC78-03BEE79951BE.exe |
Windows 7 |
45.2% |
|
Windows 10 |
26.2% |
|
Windows 8.1 |
19.0% |
|
Windows XP |
9.5% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x0036a6a4 |
Name |
Size of data |
MD5 |
.text |
3567616 |
b97318159bbcbab2581cc1faf6a27f48 |
.itext |
10240 |
d3d5f6dc20237897aa7ab45081d75680 |
.data |
51712 |
68f74a2b829f2c3c6f98043ce4bfed6d |
.bss |
0 |
00000000000000000000000000000000 |
.idata |
15872 |
b6506e13bf10b90f58d5983dc67711aa |
.didata |
3072 |
03525c15240723f99439d12e9903853b |
.edata |
512 |
93c51cf1a60d32b8d2c65fd63375332c |
.tls |
0 |
00000000000000000000000000000000 |
.rdata |
512 |
00ecdc720da50f5974de355fc101275a |
.reloc |
324096 |
cb8f822171514b7ba06175fb5a23e5da |
.rsrc |
306688 |
e564ebc911ec4b3cbef30d0e48456623 |