How to remove ___ocnsis.dll
- File Details
- Overview
- Analysis
___ocnsis.dll
The module ___ocnsis.dll has been detected as PUP.Pokki
File Details
| Product Name: |
|
| Company Name: |
|
| MD5: |
e0f4b37d8a2b7ee431af8b85b512dccc |
| Size: |
1 MB |
| First Published: |
2017-05-24 17:03:33 (8 years ago) |
| Latest Published: |
2022-05-06 23:51:58 (3 years ago) |
| Status: |
PUP.Pokki (on last analysis) |
|
| Analysis Date: |
2022-05-06 23:51:58 (3 years ago) |
Overview
| Signed By: |
Pokki |
| Status: |
Valid |
| %localappdata%\pokki\engine |
| %sysdrive%\adwcleaner\quarantine\files\zzpehwpqvddxbvcphwxftrkintlzcmtj\engine |
| %sysdrive%\adwcleaner\quarantine\files\smxwhldktsjpvqrhdqitxrnqfdllhyzw\engine |
| %sysdrive%\adwcleaner\quarantine\files\rzlabypwqahhshslrrhyisaaqvdanffs\engine |
| %sysdrive%\adwcleaner\quarantine\files\rencgubmsetfltuqokxzompwhvvkfxcf\engine |
| %sysdrive%\adwcleaner\quarantine\files\jgvcuymswhogmitmbabxkxguavovpueg\engine |
| %sysdrive%\windows.old\users\default\appdata\local\pokki\engine |
| %sysdrive%\adwcleaner\quarantine\rywtiizs2t\engine |
| %localappdata%\pokki |
| %sysdrive%\windows.old\users\default\appdata\local\pokki |
| Launcher.dll |
| ___ocnsis.dll |
|
21.7% |
|
|
10.9% |
|
|
10.1% |
|
|
8.7% |
|
|
6.5% |
|
|
5.1% |
|
|
3.6% |
|
|
3.6% |
|
|
3.6% |
|
|
2.9% |
|
|
2.9% |
|
|
2.2% |
|
|
2.2% |
|
|
2.2% |
|
|
2.2% |
|
|
1.4% |
|
|
1.4% |
|
|
1.4% |
|
|
1.4% |
|
|
0.7% |
|
|
0.7% |
|
|
0.7% |
|
|
0.7% |
|
|
0.7% |
|
|
0.7% |
|
|
0.7% |
|
|
0.7% |
|
| Windows 10 |
54.0% |
|
| Windows 8.1 |
45.3% |
|
| Windows 7 |
0.7% |
|
Analysis
| Subsystem: |
Windows GUI |
| PE Type: |
pe |
| OS Bitness: |
32 |
| Image Base: |
0x10000000 |
| Entry Address: |
0x000c98b9 |
| Name |
Size of data |
MD5 |
| .text |
1068544 |
550b17277d344ba6e6f2c95d23536ee3 |
| .rdata |
158208 |
438eb1d8c072cd5676be3be7a75b5c42 |
| .data |
22528 |
06571f8f073e8c3fd1414efa1c7ed9f4 |
| .tls |
512 |
bf619eac0cdf3f68d496ea9344137e8b |
| .rsrc |
144896 |
c911f7f85b7245afb6d8609cd3999483 |
| .reloc |
59392 |
574391726b3165238e4ffb85f7216438 |