How to remove eWorker.exe
- File Details
- Overview
- Analysis
eWorker.exe
The module eWorker.exe has been detected as Adware.Downloader
File Details
MD5: |
00a4727b3851c454b2ae2980acea0318 |
Size: |
210 KB |
First Published: |
2017-05-22 02:09:51 (7 years ago) |
Latest Published: |
2019-11-15 14:45:28 (5 years ago) |
Status: |
Adware.Downloader (on last analysis) |
|
Analysis Date: |
2019-11-15 14:45:28 (5 years ago) |
Overview
%programfiles%\dsnet corp\atube catcher 2.0 |
%sysdrive%\local disk\program files (x86)\dsnet corp\atube catcher 2.0 |
%sysdrive%\archivos de programa\dsnet corp\atube catcher 2.0 |
%sysdrive%\programmi\dsnet corp\atube catcher 2.0 |
%mydoc%\respaldo disco-toshiba-jun-2015\respaldo-hp-feb-2015\archivos disco c\program files (x86)\dsnet corp\atube catcher 2.0 |
%programfiles%\atube catcher |
%desktop%\samsung s7 edge março 17\phone\download\atubecatcher-3.8.8001\atube catcher 2.0 |
%sysdrive%\windows.old\program files (x86)\dsnet corp\atube catcher 2.0 |
%profile% |
%programfiles%\dsnet corp |
|
33.2% |
|
|
11.3% |
|
|
8.4% |
|
|
7.1% |
|
|
5.5% |
|
|
4.5% |
|
|
4.2% |
|
|
2.8% |
|
|
2.2% |
|
|
2.0% |
|
|
1.9% |
|
|
1.8% |
|
|
1.7% |
|
|
1.3% |
|
|
1.0% |
|
|
1.0% |
|
|
0.6% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
Windows 10 |
55.4% |
|
Windows 7 |
32.6% |
|
Windows 8.1 |
7.6% |
|
Windows 8 |
2.5% |
|
Windows XP |
1.7% |
|
Windows Vista |
0.2% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x00003808 |
Name |
Size of data |
MD5 |
.text |
184320 |
a36481ddef6fcd0d2246094f213b9da8 |
.data |
4096 |
620f0b67a91f7f74151bc5be745b7110 |
.rsrc |
16384 |
4de4430d402827de0fb142b9ebea80e6 |