How to remove ChromeAutoApproveTB.dll.vir
- File Details
- Overview
- Analysis
ChromeAutoApproveTB.dll.vir
The module ChromeAutoApproveTB.dll.vir has been detected as Adware.Conduit
File Details
Product Name: |
|
Company Name: |
|
MD5: |
f776bca428e4be951d4732ed3ed9706a |
Size: |
152 KB |
First Published: |
2017-10-19 14:04:44 (7 years ago) |
Latest Published: |
2019-03-28 13:45:46 (6 years ago) |
Status: |
Adware.Conduit (on last analysis) |
|
Analysis Date: |
2019-03-28 13:45:46 (6 years ago) |
Overview
%chromeprofile%\extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\10.20.101.5_0\plugins |
%localappdata%\torch\user data\default\extensions\aanjjkgbodmfkdnkkhcjcghgnibdllak\10.20.101.5_0\plugins |
%system%\config\systemprofile\appdata\local\google\chrome\user data\default\extensions\bejbohlohkkgompgecdcbbglkpjfjgdj\10.20.101.5_0 |
%localappdata%\google\chrome sxs\user data\default\extensions\nlgmkneodlhgobiipoilolfbeaelbhpc\10.20.101.5_0 |
%sysdrive%\d2\הודיה\local settings\application data\google\chrome\user data\default\extensions\jfjhiccppafcjicfalobggnophliocpp\10.20.101.5_0 |
%system%\config\systemprofile\appdata\local\google\chrome\user data\default\extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\10.20.101.5_0 |
%system%\config\systemprofile\appdata\local\google\chrome\user data\default\extensions\elhjaoldnkkbifioodjndkijecdeinld\10.20.101.5_0 |
%localappdata%\torch\user data\default\extensions\aanjjkgbodmfkdnkkhcjcghgnibdllak\10.20.101.5_0 |
%sysdrive%\adwcleaner\quarantine\c\users\owner\appdata\local\torch\user data\default\extensions\jokmfbcmohghocigimginpgjnghgepci\10.20.101.5_0 |
%sysdrive%\pasta g\windows\system32\config\systemprofile\appdata\local\google\chrome\user data\default\extensions\mdebcffgnijbblbinknkbefciofebcda\10.20.101.5_0 |
ChromeAutoApproveTB.dll |
ChromeAutoApproveTB.dll.vir |
Netherlands |
46.7% |
|
Israel |
13.3% |
|
Taiwan |
6.7% |
|
Turkey |
6.7% |
|
Russia |
6.7% |
|
Ukraine |
6.7% |
|
France |
6.7% |
|
Brazil |
6.7% |
|
Windows 10 |
60.0% |
|
Windows 7 |
33.3% |
|
Windows Vista |
6.7% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x10000000 |
Entry Address: |
0x0000cca7 |
Name |
Size of data |
MD5 |
.text |
107008 |
9604c43941075d31c9d8a799c5cb999e |
.rdata |
25088 |
adaa59564f0ebe0b86f265cc353b660d |
.data |
6144 |
b5f2099666a9c79eb65fd143ea36a6c6 |
.rsrc |
1536 |
e8d4b415604c9b0e6f2e63dcb28cb0dc |
.reloc |
8704 |
6034ad79c3856945df362ae542dede41 |