How to remove ZonaUpdater.exe.bak
- File Details
- Overview
- Analysis
ZonaUpdater.exe.bak
The module ZonaUpdater.exe.bak has been detected as PUP.Downloader
File Details
| Product Name: |
|
| Company Name: |
|
| MD5: |
f8272bfa809d068f4c3ea1845b8de76d |
| Size: |
429 KB |
| First Published: |
2017-06-29 00:02:21 (8 years ago) |
| Latest Published: |
2025-09-07 23:00:42 (2 months ago) |
| Status: |
PUP.Downloader (on last analysis) |
|
| Analysis Date: |
2025-09-07 23:00:42 (2 months ago) |
Overview
| %sysdrive%\progra~2\zona |
| %appdata%\zona\plugins\zupdater |
| %appdata%\systweak\advanced system~protector\quarantine\pua.zona |
| %programfiles%\zona |
| %sysdrive%\adwcleaner\quarantine\files\mqhmskitqoymaoufuqgicxrcxsznieaj\plugins\zupdater |
| %sysdrive%\adwcleaner\quarantine\files\cjwditwtdkhtvzdbkelcsdiectygihpm |
| %sysdrive%\adwcleaner\quarantine\files\fbydfbjppoqooezcdbsbamcsovpjgsmi |
| %sysdrive%\adwcleaner\quarantine\files\pktzuhrjnxlhfbvgvpsyacifbhzozztj |
| %sysdrive%\adwcleaner\quarantine\files\wfcmkyvsftkuabywrzhfolwzekaucegf |
| %sysdrive%\adwcleaner\quarantine\files\dfkeqrhovwaizbigadgbcwfxryqgfbbm\plugins\zupdater |
| ZonaUpdater.exe |
| ZonaUpdater.exe.bak |
| f8272bfa809d068f4c3ea1845b8de76d_080717014219048_965097792.dat |
| $R38IWVD.bak |
| ZONAUP~1.EXE |
| ZONAUP~1.EXE.quarantined |
| A0021730.exe |
| A0017805.exe |
| A0019768.exe |
|
66.0% |
|
|
16.9% |
|
|
4.6% |
|
|
2.8% |
|
|
1.6% |
|
|
1.4% |
|
|
1.2% |
|
|
1.2% |
|
|
0.7% |
|
|
0.4% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
| Windows 10 |
42.8% |
|
| Windows 7 |
41.1% |
|
| Windows 8.1 |
11.6% |
|
| Windows XP |
2.3% |
|
| Windows 8 |
1.4% |
|
| Windows Embedded 8.1 |
0.8% |
|
Analysis
| Subsystem: |
Windows GUI |
| PE Type: |
pe |
| OS Bitness: |
32 |
| Image Base: |
0x00400000 |
| Entry Address: |
0x00025777 |
| Name |
Size of data |
MD5 |
| .text |
259072 |
dc606139073257ee4ea0e3f37a5b52f0 |
| .rdata |
65024 |
204ef28fea1433669413f3d41aa850f7 |
| .data |
12800 |
7c6b1ca3cd2e1e1648d564d0a881aa03 |
| .rsrc |
77824 |
fb4ba6fbb3f2faabef118d378b38e738 |
| .reloc |
17408 |
11bcf9feceaeed1f1f253ffb258bf9b4 |