How to remove GuardMailRu829[1].exe
- File Details
- Overview
- Analysis
GuardMailRu829[1].exe
The module GuardMailRu829[1].exe has been detected as PUP.MailRu
File Details
| Product Name: |
|
| MD5: |
23e0d74c0f11124c53743a950fe0621b |
| Size: |
3 MB |
| First Published: |
2017-06-01 06:10:24 (8 years ago) |
| Latest Published: |
2021-05-11 20:23:59 (4 years ago) |
| Status: |
PUP.MailRu (on last analysis) |
|
| Analysis Date: |
2021-05-11 20:23:59 (4 years ago) |
Overview
| %commonappdata%\guard.mail.ru |
| %profile%\ocalservice\local settings\temporary internet files\content.ie5\qhqter6x |
| %programfiles%\mail.ru\guard |
| %system%\config\systemprofile\appdata\local\microsoft\windows\temporary internet files\content.ie5\tvvmfaux |
| %system%\config\systemprofile\appdata\local\microsoft\windows\temporary internet files\content.ie5\0ps72r2m |
| %system%\config\systemprofile\appdata\local\microsoft\windows\temporary internet files\content.ie5\q716l5dl |
| %profile%\ocalservice\local settings\temporary internet files\content.ie5\e9p83d26 |
| %system%\config\systemprofile\appdata\local\microsoft\windows\temporary internet files\content.ie5 |
| %commonappdata% |
| %profile%\ocalservice\local settings\temporary internet files\content.ie5 |
| GuardMailRu.exe |
| GuardMailRu829[1].exe |
| GuardMailRu.exe.quarantined |
| 2A340D1BCAC84D7FAC9136DBA1DA423C.exe |
| GuardMailRu.exe#FDD84FBE51A2D620 |
| GuardMailRu829[10].exe |
| 49493B4B459145BFAEFA2F989096B585.exe |
| 001DF0DFE0734E00A8FA4885B9176A48.exe |
|
53.3% |
|
|
13.9% |
|
|
6.7% |
|
|
5.0% |
|
|
3.9% |
|
|
2.8% |
|
|
2.2% |
|
|
2.2% |
|
|
1.7% |
|
|
1.1% |
|
|
1.1% |
|
|
0.6% |
|
|
0.6% |
|
|
0.6% |
|
|
0.6% |
|
|
0.6% |
|
|
0.6% |
|
|
0.6% |
|
|
0.6% |
|
|
0.6% |
|
|
0.6% |
|
|
0.6% |
|
| Windows 7 |
78.7% |
|
| Windows 10 |
10.9% |
|
| Windows XP |
9.3% |
|
| Windows Vista |
0.5% |
|
| Windows 8.1 |
0.5% |
|
Analysis
| Subsystem: |
Windows GUI |
| PE Type: |
pe |
| OS Bitness: |
32 |
| Image Base: |
0x00400000 |
| Entry Address: |
0x001e838c |
| Name |
Size of data |
MD5 |
| .text |
2934784 |
d452c70034aa7decdb001b212f590018 |
| .rdata |
594432 |
5f9fc8edbf9299d5cb69aff5c0a3e6e6 |
| .data |
54784 |
c71c791716d4c57a211f042a21deb1e1 |
| .tls |
512 |
bf619eac0cdf3f68d496ea9344137e8b |
| .rsrc |
205824 |
53c0a1a54582c22574675080a5c5b2cb |
| .reloc |
157184 |
75b84063b4988405e103a6e122e73c8a |