How to remove Action.exe
Action.exe
The module Action.exe has been detected as Trojan.Agent
File Details
Product Name: | WindowsFormsApplication5 |
Company Name: | Microsoft |
MD5: | 0f42d9c145c13ef0ef04952715f98933 |
Size: | 103 KB |
First Published: | 2017-11-17 10:05:16 (7 years ago) |
Latest Published: | 2021-09-14 20:59:28 (3 years ago) |
Status: | Trojan.Agent (on last analysis) | |
Analysis Date: | 2021-09-14 20:59:28 (3 years ago) |
Common Places:
%desktop%\pavan workspase\struts_hibernate\webcontent\web-inf |
%desktop%\pavan workspase\struts_hibernate\build\classes\com\action |
%desktop%\pavan workspase\.metadata\.plugins\org.eclipse.wst.server.core\tmp1\wtpwebapps\struts_hibernate\web-inf |
%desktop%\pavan workspase\struts_hibernate\build\classes\com\pojo |
%desktop%\pavan workspase\struts_hibernate\src\com\action |
%startup% |
%mydoc% |
%sysdrive%\ \files are hidden by trojan\hand book 2017 |
%sysdrive%\ \files are hidden by trojan\hand book 2019 |
%sysdrive%\ \files are hidden by trojan |
File Names:
WEB-INF.exe |
Action.exe |
pojo.exe |
svchost..exe |
suchost..exe |
Geography:
81.9% | ||
18.1% |
OS Version:
Windows 7 | 75.0% | |
Windows 10 | 25.0% |
Analysis
Subsystem: | Windows GUI |
PE Type: | pe |
OS Bitness: | 32 |
Image Base: | 0x00400000 |
Entry Address: | 0x00005e1e |
.NET Info:
MVID: | e395e0e4-dd99-4c0b-950a-1917cd4ef52a |
Typelib ID: | c427b839-4281-417b-85d9-a6960db7031f |
PE Sections:
Name | Size of data | MD5 |
.text | 16384 | 242e0d960640a9d175bf53676622f88e |
.rsrc | 88576 | e0bed19ad0db49b2ecb5cdec6d24c0c9 |
.reloc | 512 | e0c790d5b83f9cbbe36101923384322c |
More information:
Download GridinSoft
Anti-Malware - Removal tool for Action.exe