How to remove air9BD5.exe
- File Details
- Overview
- Analysis
air9BD5.exe
The module air9BD5.exe has been detected as Adware.InstallIQ
File Details
Product Name: |
|
Company Name: |
|
MD5: |
05853d32be533b54b6e53c5728b2d997 |
Size: |
914 KB |
First Published: |
2018-05-11 06:02:32 (6 years ago) |
Latest Published: |
2018-05-11 06:02:32 (6 years ago) |
Status: |
Adware.InstallIQ (on last analysis) |
|
Analysis Date: |
2018-05-11 06:02:32 (6 years ago) |
Overview
Signed By: |
W3i, LLC |
Status: |
Invalid (digital signature could be stolen or file could be patched) |
%sysdrive%\e machine cts\desktop\back up for green flash drive\new folder (3)\users\appdata\local |
%sysdrive%\e machine cts\desktop\back up for green flash drive\new folder (3)\users\maroc\appdata\local |
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x0001ab29 |
Name |
Size of data |
MD5 |
.text |
198144 |
cce0a0404fcd7d5ea9ef12772f6b9fd1 |
.text-co |
81408 |
2ca9044097a95e26ac665534bf0889a1 |
.text-co |
26112 |
1d580fc620096e9c5be6cb6744f44567 |
.text-ti |
41984 |
2bcdc76538f0d6e784d6200b77e63856 |
.text-co |
254976 |
22020e0c4bd510defa0ed4d34f01552e |
.text-co |
10752 |
2e9268992f2465cbb88f798898ac67dd |
.text-co |
12800 |
6e4a22dc13f6c55c615c8b226a1f8d56 |
.text-co |
21504 |
7934bbbc590793f4308e30d9ed16f95b |
.text-co |
43008 |
5438f00cefe6b211c8d0fadbe06113da |
.rdata |
132608 |
7cc040a089af91baa0956fa906a15c26 |
.data |
10752 |
2bce12cf2aba2a04ece7702c2d6a2c6d |
.data-co |
512 |
bf619eac0cdf3f68d496ea9344137e8b |
.data-co |
512 |
3617374ba9e0a53ae8e4ec907bf3b8b4 |
.data-co |
512 |
bf619eac0cdf3f68d496ea9344137e8b |
.data-co |
512 |
bf619eac0cdf3f68d496ea9344137e8b |
.data-co |
512 |
bf619eac0cdf3f68d496ea9344137e8b |
.data-co |
3072 |
280f2fae1d4bfbd3c66d42e8f83bc8d3 |
.data-ti |
1536 |
a1054bf61ec2177512e7fd764956ad63 |
.data-co |
512 |
722c904b1bbb1c9cb01609954e9a3f1f |
.rsrc |
56832 |
36e602973c9f6dd3275500b9351fb21c |
.reloc |
32768 |
efedca5c5f5266e890ce6f43b9131508 |