How to remove db49f02a-8526-4b0b-9907-31e526e4e84c.tmp
- File Details
- Overview
- Analysis
db49f02a-8526-4b0b-9907-31e526e4e84c.tmp
The module db49f02a-8526-4b0b-9907-31e526e4e84c.tmp has been detected as PUP.MailRu
File Details
Product Name: |
|
Company Name: |
|
MD5: |
5300ccf349aaec963863a9b94898f4ab |
Size: |
1 MB |
First Published: |
2018-03-13 12:06:35 (6 years ago) |
Latest Published: |
2021-01-15 12:32:21 (4 years ago) |
Status: |
PUP.MailRu (on last analysis) |
|
Analysis Date: |
2021-01-15 12:32:21 (4 years ago) |
Overview
%localappdata%\amigo\application\61.0.3163.125 |
%appdata%\pointstone\system cleaner\backups\ac3b0953-57f6-40fc-b2d0-1f2bd389a9c6.zip\c:\users\администратор\appdata\local\temp |
%temp% |
%sysdrive%\adwcleaner\quarantine\ozyfyz5b6k\application\61.0.3163.125 |
%sysdrive%\admin-uxddnrhjk\backup set 2018-04-01 190007\backup files 2018-04-01 190007\backup files 6.zip\c\users\игры\appdata\local\amigo\application\61.0.3163.125 |
%sysdrive%\adwcleaner\quarantine\1xvpfvjcrg\application\61.0.3163.125 |
%localappdata%\amigo\application\61.0.3163.125 |
%localappdata%\amigo\application\61.0.3163.125 |
%localappdata%\amigo\application\61.0.3163.125 |
%temp% |
setup.exe |
db49f02a-8526-4b0b-9907-31e526e4e84c.tmp |
|
75.1% |
|
|
7.5% |
|
|
5.1% |
|
|
4.0% |
|
|
3.2% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
Windows 10 |
44.7% |
|
Windows 7 |
40.8% |
|
Windows 8.1 |
12.2% |
|
Windows 8 |
2.4% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x000b4bb0 |
Name |
Size of data |
MD5 |
.text |
988160 |
9af660d4765f1c0830bb1d6ae5ad0a34 |
.rdata |
164864 |
c4f4b2ebaa8f079becf01efd98b14899 |
.data |
4608 |
96d76e58b9d2d87fdcc8398ab8d29a05 |
.didat |
512 |
9ff42f910e35ba60a176117c204ec431 |
CPADinfo |
512 |
d273139d7dd4280f40c57791927d34c6 |
.tls |
512 |
1f354d76203061bfdd5a53dae48d5435 |
.rsrc |
170496 |
ab626163b110ce063e4fc10d9417269a |
.reloc |
30720 |
0b8c4e70e396cacca51841dc59681f7a |