How to remove GuardMailRu[1].exe
- File Details
- Overview
- Analysis
GuardMailRu[1].exe
The module GuardMailRu[1].exe has been detected as PUP.MailRu
File Details
| Product Name: |
|
| MD5: |
96a768dd52ff0115fff85142056b3af0 |
| Size: |
2 MB |
| First Published: |
2017-06-27 18:04:17 (8 years ago) |
| Latest Published: |
2021-12-28 21:18:24 (4 years ago) |
| Status: |
PUP.MailRu (on last analysis) |
|
| Analysis Date: |
2021-12-28 21:18:24 (4 years ago) |
Overview
| %system%\config\systemprofile\appdata\local\microsoft\windows\temporary internet files\content.ie5\tl5v1ma9 |
| %system%\config\systemprofile\appdata\local\microsoft\windows\temporary internet files\content.ie5\62axopq5 |
| %commonappdata%\guard.mail.ru |
| %programfiles%\mail.ru\guard |
| %system%\config\systemprofile\appdata\local\microsoft\windows\temporary internet files\content.ie5\nnjvh9rb |
| %system%\config\systemprofile\appdata\local\microsoft\windows\temporary internet files\content.ie5\2b8w0osc |
| %sysdrive%\c\program files\mail.ru\guard |
| %system%\config\systemprofile\appdata\local\microsoft\windows\temporary internet files\content.ie5 |
| %sysdrive%\bamp\румянцев корень с\комп2\documents and settings\all users\application data |
| %sysdrive%\bamp\румянцев корень с\комп2\documents and settings\localservice\local settings\temporary internet files\content.ie5 |
| GuardMailRu[2].exe |
| GuardMailRu[1].exe |
| GuardMailRu.exe |
| GuardMailRu[3].exe |
|
39.7% |
|
|
31.5% |
|
|
23.3% |
|
|
2.7% |
|
|
2.7% |
|
| Windows 7 |
83.6% |
|
| Windows 10 |
13.7% |
|
| Windows XP |
2.7% |
|
Analysis
| Subsystem: |
Windows GUI |
| PE Type: |
pe |
| OS Bitness: |
32 |
| Image Base: |
0x00400000 |
| Entry Address: |
0x000e84a0 |
| Name |
Size of data |
MD5 |
| .text |
1709056 |
082f848a00d958b30f72aa9f9a9d38b8 |
| .rdata |
314368 |
8726c45af9b048f076d09c0a3523d37a |
| .data |
38912 |
e66c2a4b54a2f65adb78c6c7fd542971 |
| .tls |
512 |
bf619eac0cdf3f68d496ea9344137e8b |
| .rsrc |
80384 |
d300f2a800a645f4fc1691cec9c4c416 |
| .reloc |
111104 |
75fc182484da9b3c6d23bb5f5bd6ae5b |