How to remove SaUpdate.exe
- File Details
- Overview
- Analysis
SaUpdate.exe
The module SaUpdate.exe has been detected as Hijack.IE
File Details
MD5: |
7ec86785186daf9e7f36ab5fce3a7f3b |
Size: |
190 KB |
First Published: |
2017-06-16 01:06:52 (8 years ago) |
Latest Published: |
2021-12-16 21:25:26 (3 years ago) |
Status: |
Hijack.IE (on last analysis) |
|
Analysis Date: |
2021-12-16 21:25:26 (3 years ago) |
Overview
%programfiles%\ask.com |
%sysdrive%\system volume information\_restore{e15bc74f-4302-4f1f-8d48-100940ab2529} |
%programfiles% |
%sysdrive%\recycler\s-1-5-21-117609710-813497703-682003330-500 |
%sysdrive%\adwcleaner\quarantine\v1\20180611.202741\54 |
%programfiles% |
%programfiles% |
%sysdrive%\all_data\program files (x86) |
%programfiles% |
%programfiles% |
saupdate.exe |
SaUpdate.exe |
A0025502.exe |
SaUpdate.exe#798FB7102CADC2FE |
|
58.6% |
|
|
11.4% |
|
|
5.7% |
|
|
4.3% |
|
|
4.3% |
|
|
2.9% |
|
|
2.9% |
|
|
2.9% |
|
|
1.4% |
|
|
1.4% |
|
|
1.4% |
|
|
1.4% |
|
|
1.4% |
|
Windows 7 |
81.4% |
|
Windows 10 |
11.4% |
|
Windows 8 |
4.3% |
|
Windows XP |
2.9% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x000168ca |
Name |
Size of data |
MD5 |
.text |
145920 |
7ffaaf613a803e93de6c03f88a477869 |
.rdata |
22016 |
d96ec1d8c03011cd6e5b40cac651697c |
.data |
7168 |
01d08dc3dab604be77b7cc6539b0d415 |
.rsrc |
512 |
62a94a06293dde02247bcdfffaa10abd |
.reloc |
11264 |
944e78495256066f706c0ae053fd17b8 |