How to remove A0162909.exe
- File Details
- Overview
- Analysis
A0162909.exe
The module A0162909.exe has been detected as Trojan.Agent
File Details
Product Name: |
|
Company Name: |
|
MD5: |
39f09e731785c9be8f73a454936855fd |
Size: |
1 MB |
First Published: |
2018-07-05 15:07:06 (6 years ago) |
Latest Published: |
2018-07-09 14:12:53 (6 years ago) |
Status: |
Trojan.Agent (on last analysis) |
|
Analysis Date: |
2018-07-09 14:12:53 (6 years ago) |
Overview
%programfiles%\gretech |
%appdata%\gretech |
%sysdrive%\new folder (9) |
%sysdrive%\windows.old\users\蘇進欽\appdata\roaming\gretech |
%sysdrive% |
%sysdrive%\system volume information\_restore{fb46a10d-1c8e-44d1-b3c7-6beb86542341} |
%sysdrive%\_genie timeline\0\c\windows.old\users\ägaren\appdata\roaming\gretech\gomaudio |
%programfiles%\gom |
%sysdrive%\other\programmki |
GrLauncher.exe |
A0162909.exe |
A0162968.exe |
grlauncher.exe |
|
11.9% |
|
|
11.9% |
|
|
8.5% |
|
|
7.6% |
|
|
5.9% |
|
|
5.9% |
|
|
5.9% |
|
|
5.1% |
|
|
4.2% |
|
|
3.4% |
|
|
3.4% |
|
|
3.4% |
|
|
2.5% |
|
|
2.5% |
|
|
2.5% |
|
|
2.5% |
|
|
1.7% |
|
|
1.7% |
|
|
1.7% |
|
|
1.7% |
|
|
1.7% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
Windows 10 |
58.3% |
|
Windows 7 |
28.3% |
|
Windows 8.1 |
9.2% |
|
Windows 8 |
2.5% |
|
Windows XP |
1.7% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x0012a772 |
Name |
Size of data |
MD5 |
.text |
1399808 |
a62b028bcfa3128e2b590938586dde57 |
.rdata |
335360 |
e687418e002cdcefa025124634eb49fb |
.data |
27136 |
3e0c00e87842e9f68266521ce74b11fd |
.rsrc |
120320 |
edae748fbd6962dedc8d06d0119b919f |
.reloc |
121856 |
00a84754953b42cfc7cf590f7b60ef8a |