How to remove edrwkgn.exe
- File Details
- Overview
- Analysis
edrwkgn.exe
The module edrwkgn.exe has been detected as Rootkit.Gen
File Details
Product Name: |
|
MD5: |
1974c88979debfe710d597fff868d0e5 |
Size: |
3 MB |
First Published: |
2020-09-21 10:34:40 (4 years ago) |
Latest Published: |
2024-10-31 23:07:01 (3 months ago) |
Status: |
Rootkit.Gen (on last analysis) |
|
Analysis Date: |
2024-10-31 23:07:01 (3 months ago) |
Overview
%profile%\downloads\programs\easeus.data.recovery.wizard.technician.13.6.0.portable\app |
%profile%\downloads\programs\easeus.data.recovery.wizard.technician.13.6.0.portable\app |
%sysdrive%\$recycle.bin\s-1-5-21-3730955377-3262736296-847835398-1001\$rzjcz0i.7z\easeusdatarecoverywizard\app |
%sysdrive%\$recycle.bin\s-1-5-21-3730955377-3262736296-847835398-1001\$rzjcz0i.7z\easeusdatarecoverywizard\app |
%desktop%\subhash\easeus data recovery wizard te 13.5 full version\easeusdatarecoverywizard\app |
%desktop%\subhash\easeus data recovery wizard te 13.5 full version\easeusdatarecoverywizard\app |
%programfiles%\easeus |
%desktop%\soft\13.6 ok pass\easeus data recovery wizard te 13.6 full version\easeusdatarecoverywizard\app |
%desktop%\soft\13.6 ok pass\easeus data recovery wizard te 13.6 full version\easeusdatarecoverywizard\app |
%temp%\rarsfx0\easeus data recovery_x64\app |
|
33.3% |
|
|
16.7% |
|
|
16.7% |
|
|
16.7% |
|
|
8.3% |
|
|
8.3% |
|
Windows 10 |
46.2% |
|
Windows 7 |
38.5% |
|
Windows 8.1 |
15.4% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x002305f4 |
Name |
Size of data |
MD5 |
.text |
2281984 |
d4fd15019d077f4c186197bc56e207af |
.itext |
6144 |
428dbd02b48bcc62de2734a5866ce7d6 |
.data |
37376 |
7688bf05365d691faf37aa8ad213d008 |
.bss |
0 |
00000000000000000000000000000000 |
.idata |
12800 |
a75268841d2276c894b693a1a08c4908 |
.didata |
3072 |
6041a3a577a4bad0208c6f60bfdf459f |
.edata |
512 |
75c0b5d43524db85a6c7b24266c6873c |
.tls |
0 |
00000000000000000000000000000000 |
.rdata |
512 |
597c567ca004669128fd0786f81dd70c |
.reloc |
206336 |
b050c170017b7fc0d3c4797706a0b776 |
.rsrc |
601600 |
1d633b3fb592df2313840eb297060c34 |