How to remove A0195964.exe
- File Details
- Overview
- Analysis
A0195964.exe
The module A0195964.exe has been detected as Adware.Funshion
File Details
Product Name: |
|
MD5: |
016df15c4682797423cbdca5339f977e |
Size: |
667 KB |
First Published: |
2017-09-04 16:09:53 (7 years ago) |
Latest Published: |
2020-03-27 07:37:44 (4 years ago) |
Status: |
Adware.Funshion (on last analysis) |
|
Analysis Date: |
2020-03-27 07:37:44 (4 years ago) |
Overview
%sysdrive%\system volume information\_restore{ab745cfb-68f6-40e9-b0db-3eb1865a6002} |
%profile%\funshion |
%sysdrive%\cb\tony zhang\meiqinlin\funshion |
FunshionDoctor.exe |
A0195964.exe |
Windows 7 |
50.0% |
|
Windows XP |
25.0% |
|
Windows Server 2008 R2 |
25.0% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x0004964d |
Name |
Size of data |
MD5 |
.text |
448512 |
5e0b5e4b9c8e3aa0cb5fb702042e5390 |
.rdata |
84480 |
09776d33dfcd5ce0b15937ad0e54f75f |
.data |
13824 |
2f17f71e0598589f70ae4231ce2c16a1 |
.rsrc |
86528 |
b9e3b60015e4f609b991873229207f91 |
.reloc |
43008 |
cb0ed9855f7f9886487e16c09137d24d |