How to remove efo.exe
efo.exe
The module efo.exe has been detected as PUP.SystemOptimizer
File Details
Product Name: | EasyFileOpener |
MD5: | addc116ad43f81ed78c887245dd53609 |
Size: | 70 KB |
First Published: | 2017-05-22 09:04:18 (7 years ago) |
Latest Published: | 2020-12-19 23:51:40 (4 years ago) |
Status: | PUP.SystemOptimizer (on last analysis) | |
Analysis Date: | 2020-12-19 23:51:40 (4 years ago) |
Overview
Signed By: | advanced pc care |
Status: | Valid |
Common Places:
%appdata%\efo |
%sysdrive%\adwcleaner\quarantine\files\skuzltkskbwiueljogkguuezrnqahcku |
%sysdrive%\adwcleaner\quarantine\files\fwhvzjcgclyxzlbfpggroeygwiqkptgb |
%sysdrive%\adwcleaner\quarantine\files\ppoxhkrtnylwyszpdabcbxmvnjveyjkp |
%appdata% |
%profile%\dministrator\application data |
%sysdrive%\adwcleaner\quarantine\files |
%profile%\dmin\application data |
%sysdrive%\acer-pc\backup set 2016-09-27 022041\backup files 2016-10-02 190005\backup files 1.zip\c\users\acer\appdata\roaming |
%sysdrive%\$recycle.bin\s-1-5-21-3170223018-4099311740-948965009-1000\$rf8vvbl\backup set 2017-01-01 190005\backup files 2017-01-01 190005\backup files 1.zip\c\users\win 7\appdata\roaming |
Geography:
41.3% | ||
14.3% | ||
11.9% | ||
7.9% | ||
4.0% | ||
3.2% | ||
3.2% | ||
1.6% | ||
1.6% | ||
1.6% | ||
1.6% | ||
0.8% | ||
0.8% | ||
0.8% | ||
0.8% | ||
0.8% | ||
0.8% | ||
0.8% | ||
0.8% | ||
0.8% | ||
0.8% |
OS Version:
Windows 7 | 60.3% | |
Windows 10 | 31.0% | |
Windows 8.1 | 4.8% | |
Windows XP | 1.6% | |
Windows 8 | 1.6% | |
Windows Server 2003 | 0.8% |
Analysis
Subsystem: | Windows GUI |
PE Type: | pe |
OS Bitness: | 32 |
Image Base: | 0x00400000 |
Entry Address: | 0x0000cf32 |
.NET Info:
MVID: | 740659d6-eec6-4a32-8be8-3e0903d14168 |
Typelib ID: | f1253aae-6e03-4338-a23d-bdfe3a6f3cdf |
PE Sections:
Name | Size of data | MD5 |
.text | 45056 | 19423b1fa40da6adb8a632858e2f76dd |
.reloc | 512 | c11235c124b4b0223b5faf01ea4e4e6f |
.rsrc | 19456 | 42899ca1df1afc5cb2add951c7343060 |
More information:
Download GridinSoft
Anti-Malware - Removal tool for efo.exe