How to remove WinToUSB Activator v1.0.exe
- File Details
- Overview
- Analysis
WinToUSB Activator v1.0.exe
The module WinToUSB Activator v1.0.exe has been detected as Trojan.Agent
File Details
| Product Name: |
|
| Company Name: |
|
| MD5: |
a7db7ff09b87d9bc3a2eeb53976a5e5d |
| Size: |
1 MB |
| First Published: |
2020-07-27 14:01:11 (5 years ago) |
| Latest Published: |
2022-08-02 23:25:46 (3 years ago) |
| Status: |
Trojan.Agent (on last analysis) |
|
| Analysis Date: |
2022-08-02 23:25:46 (3 years ago) |
| %sysdrive%\tor downloads\wintousb (all editions) 5.5 + activator\wintousb (all editions) 5.5 + activator\activator |
| %sysdrive%\$recycle.bin |
| %profile%\downloads\[ftuapps.com] - wintousb 5.6 all editions multilingual + activator |
| %profile%\downloads\wintousb 5.6 r1 multilingual |
| %sysdrive%\programs\win to usb\wintousb v5.6\wintousb activator v1.0.7z |
| %desktop%\desktop icons\wintousb\wintousb_enterprise_5.5_release_1_multilingual |
| %programfiles%\hasleo |
| %sysdrive%\05 my software 01\wintousb 5.5 release 1 all editions + activator\wintousb 5.5 release 1 all editions + activator\activator |
| %sysdrive%\downloads\wintousb 5.6 enterprise professional technician.zip\wintousb 5.6 multilingual |
| %programfiles%\hasleo |
|
17.6% |
|
|
11.8% |
|
|
11.8% |
|
|
5.9% |
|
|
5.9% |
|
|
5.9% |
|
|
5.9% |
|
|
5.9% |
|
|
5.9% |
|
|
5.9% |
|
|
5.9% |
|
|
5.9% |
|
|
5.9% |
|
| Windows 10 |
76.5% |
|
| Windows 8.1 |
11.8% |
|
| Windows 7 |
11.8% |
|
Analysis
| Subsystem: |
Windows GUI |
| PE Type: |
pe |
| OS Bitness: |
32 |
| Image Base: |
0x00400000 |
| Entry Address: |
0x0001181c |
| Name |
Size of data |
MD5 |
| .text |
62464 |
0da5d73ffbc41792fa65a09058a91476 |
| .itext |
4096 |
2eb275566563c3f1d0099a0da7345b74 |
| .data |
3584 |
73b859e23f5fd17e00c08db2e0e73dfe |
| .bss |
0 |
d41d8cd98f00b204e9800998ecf8427e |
| .idata |
4096 |
e9b9c0328fd9628ad4d6ab8283dcb20e |
| .tls |
0 |
d41d8cd98f00b204e9800998ecf8427e |
| .rdata |
512 |
3dffc444ccc131c9dcee18db49ee6403 |
| .rsrc |
178176 |
9cf18c7c09737e8295c8c2d336eda648 |