How to remove driverrestore.exe
- File Details
- Overview
- Analysis
driverrestore.exe
The module driverrestore.exe has been detected as Hijack.Explorer
File Details
Product Name: |
|
MD5: |
70abe717d548155c79d0c9c1694f65b0 |
Size: |
719 KB |
First Published: |
2017-08-15 03:10:10 (7 years ago) |
Latest Published: |
2020-10-30 00:48:13 (4 years ago) |
Status: |
Hijack.Explorer (on last analysis) |
|
Analysis Date: |
2020-10-30 00:48:13 (4 years ago) |
Overview
%programfiles%\driverrestore |
%desktop%\nkt 2017\nhà b tgð\driverrestore |
%programfiles% |
%desktop%\documentos\webcam |
%sysdrive%\adwcleaner\quarantine |
%sysdrive%\$recycle.bin |
%desktop%\backup\document\drivers |
%programfiles% |
%programfiles% |
%programfiles% |
DriverRestore.exe |
driverrestore.exe |
$RT3PD6G.exe |
|
39.8% |
|
|
11.4% |
|
|
9.1% |
|
|
6.8% |
|
|
5.7% |
|
|
4.5% |
|
|
3.4% |
|
|
3.4% |
|
|
3.4% |
|
|
3.4% |
|
|
2.3% |
|
|
2.3% |
|
|
1.1% |
|
|
1.1% |
|
|
1.1% |
|
|
1.1% |
|
Windows 10 |
64.8% |
|
Windows 7 |
15.9% |
|
Windows 8.1 |
11.4% |
|
Windows 8 |
8.0% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x000aea3e |
MVID: |
c0b88b5d-8ad0-4e48-ba8e-4e4ea131f37c |
Typelib ID: |
fddaebaf-1174-4b8f-b708-034f2f27ca86 |
Name |
Size of data |
MD5 |
.text |
707584 |
b281dd8934192d0856f0d73bf069d2cc |
.rsrc |
20480 |
86ed60dc0cff63ee403740b43ebae4a4 |
.reloc |
512 |
a8123ac2736db99dbccd4d44bb31040c |