How to remove alternateshell.exe
- File Details
- Overview
- Analysis
alternateshell.exe
The module alternateshell.exe has been detected as Suspicious Object
File Details
| MD5: |
9ec3d89978c9a2ea2a7454d2913d79d2 |
| Size: |
95 KB |
| First Published: |
2017-09-06 15:09:00 (8 years ago) |
| Latest Published: |
2024-08-10 23:01:35 (a year ago) |
| Status: |
Suspicious Object (on last analysis) |
|
| Analysis Date: |
2024-08-10 23:01:35 (a year ago) |
Overview
| Signed By: |
JWTS |
| Status: |
Valid |
| %sysdrive%\programdata |
| %sysdrive%\wsession |
| %profile% |
| %commonappdata% |
| %sysdrive% |
| %commonappdata% |
| %commonappdata% |
| %commonappdata% |
| %commonappdata% |
| %sysdrive% |
| uninst.exe |
| alternateshell.exe |
| removelastfolders.exe |
| logonsession.exe |
| myremoteapp.exe |
| cl.1497297930.bdinstall.exe |
| dm.1497298270.bdinstall.exe |
| agent.1497297800.bdinstall.exe |
| agent.update.1497297924.bdinstall.exe |
| dm.uninstall.1497300184.bdinstall.exe |
| cl.uninstall.1510940932.bdinstall.exe |
| MyRemoteApp.exe |
|
66.9% |
|
|
10.9% |
|
|
4.5% |
|
|
2.9% |
|
|
2.9% |
|
|
2.5% |
|
|
2.1% |
|
|
1.5% |
|
|
1.1% |
|
|
1.1% |
|
|
0.8% |
|
|
0.8% |
|
|
0.7% |
|
|
0.6% |
|
|
0.3% |
|
|
0.3% |
|
| Windows 10 |
94.8% |
|
| Windows 7 |
4.4% |
|
| Windows 8.1 |
0.8% |
|
Analysis
| Subsystem: |
Windows GUI |
| PE Type: |
pe |
| OS Bitness: |
32 |
| Image Base: |
0x00400000 |
| Entry Address: |
0x0000142f |
| Name |
Size of data |
MD5 |
| .text |
18432 |
bfe456f7a3fdcdf87f19fab9c5282cfa |
| .rdata |
8704 |
6fa22570a9a1b4e35307a9afeb4266f3 |
| .data |
3072 |
620b9cb1222dfbdffbd6f90fa59cdf84 |
| .rsrc |
56832 |
1c6847ff955d6e7e31e237b103edf39a |
| .reloc |
2560 |
44f6a563cee2cdbab78017f67b876d93 |