How to remove A0004352.exe
- File Details
- Overview
- Analysis
A0004352.exe
The module A0004352.exe has been detected as Trojan.Dapato
File Details
Product Name: |
|
Company Name: |
|
MD5: |
e5bf18aa0ab27a58c2c676b62c3b9402 |
Size: |
45 MB |
First Published: |
2018-06-22 04:12:33 (6 years ago) |
Latest Published: |
2019-04-09 15:48:35 (5 years ago) |
Status: |
Trojan.Dapato (on last analysis) |
|
Analysis Date: |
2019-04-09 15:48:35 (5 years ago) |
%profile%\olodia\мої документи |
%profile%\downloads\repack of adguard\soft |
%sysdrive%\system volume information\_restore{12497549-d79d-440e-b5bc-9b2f90ba0805} |
%sysdrive% |
%sysdrive%\wpi iso\новая папка\chip_bs\soft |
%sysdrive%\!drv |
%profile%\olodia\local settings\temp |
%sysdrive%\recycler\s-1-5-21-117609710-484763869-1644491937-1003 |
%sysdrive%\mini wpi beslam™ edition [v1.6]\softinst |
%sysdrive%\files\ильенкова\soft |
RuntimePack_x86_x64.exe |
A0004352.exe |
RuntimePack.exe |
RuntimePack12.12.10.exe |
RuntimePack v12.12.10 (x86-x64).exe |
Runtime_Pack.exe |
|
44.4% |
|
|
38.9% |
|
|
5.6% |
|
|
5.6% |
|
|
5.6% |
|
Windows 7 |
72.2% |
|
Windows XP |
22.2% |
|
Windows 8.1 |
5.6% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x0001609f |
Name |
Size of data |
MD5 |
.text |
89088 |
fd9a41c6111e51feedcd6ef0daac0015 |
.rdata |
14848 |
2f19c337c3d186deb69df3d26b786be2 |
.data |
2560 |
c306b01da1b8194bbf5865e805a016c1 |
.rsrc |
28160 |
01497fc78057141a788f694e495855da |