How to remove alternateshell.exe
- File Details
- Overview
- Analysis
alternateshell.exe
The module alternateshell.exe has been detected as Suspicious Object
File Details
MD5: |
9ec3d89978c9a2ea2a7454d2913d79d2 |
Size: |
95 KB |
First Published: |
2017-09-06 15:09:00 (7 years ago) |
Latest Published: |
2024-08-10 23:01:35 (5 months ago) |
Status: |
Suspicious Object (on last analysis) |
|
Analysis Date: |
2024-08-10 23:01:35 (5 months ago) |
Overview
Signed By: |
JWTS |
Status: |
Valid |
%sysdrive%\programdata |
%sysdrive%\wsession |
%profile% |
%commonappdata% |
%sysdrive% |
%commonappdata% |
%commonappdata% |
%commonappdata% |
%commonappdata% |
%sysdrive% |
uninst.exe |
alternateshell.exe |
removelastfolders.exe |
logonsession.exe |
myremoteapp.exe |
cl.1497297930.bdinstall.exe |
dm.1497298270.bdinstall.exe |
agent.1497297800.bdinstall.exe |
agent.update.1497297924.bdinstall.exe |
dm.uninstall.1497300184.bdinstall.exe |
cl.uninstall.1510940932.bdinstall.exe |
MyRemoteApp.exe |
|
66.9% |
|
|
10.9% |
|
|
4.5% |
|
|
2.9% |
|
|
2.9% |
|
|
2.5% |
|
|
2.1% |
|
|
1.5% |
|
|
1.1% |
|
|
1.1% |
|
|
0.8% |
|
|
0.8% |
|
|
0.7% |
|
|
0.6% |
|
|
0.3% |
|
|
0.3% |
|
Windows 10 |
94.8% |
|
Windows 7 |
4.4% |
|
Windows 8.1 |
0.8% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x0000142f |
Name |
Size of data |
MD5 |
.text |
18432 |
bfe456f7a3fdcdf87f19fab9c5282cfa |
.rdata |
8704 |
6fa22570a9a1b4e35307a9afeb4266f3 |
.data |
3072 |
620b9cb1222dfbdffbd6f90fa59cdf84 |
.rsrc |
56832 |
1c6847ff955d6e7e31e237b103edf39a |
.reloc |
2560 |
44f6a563cee2cdbab78017f67b876d93 |