How to remove fkabvesvsqgthlvmvodikjvdrfdimmqt.back
- File Details
- Overview
- Analysis
fkabvesvsqgthlvmvodikjvdrfdimmqt.back
The module fkabvesvsqgthlvmvodikjvdrfdimmqt.back has been detected as PUP.Systweak
File Details
Product Name: |
|
Company Name: |
|
MD5: |
9222dc807ff095358467458f9dc14bc1 |
Size: |
21 KB |
First Published: |
2017-05-21 15:03:44 (7 years ago) |
Latest Published: |
2024-03-10 23:23:49 (8 months ago) |
Status: |
PUP.Systweak (on last analysis) |
|
Analysis Date: |
2024-03-10 23:23:49 (8 months ago) |
Overview
%windir%\system32 |
%sysdrive%\windows.old.000\windows\system32 |
%sysdrive%\adwcleaner\quarantine\idcdjoyapn |
%programfiles%\panda security\panda security protection\kosz |
%sysdrive%\adwcleaner\quarantine\jboh8s4kwi |
%system% |
%sysdrive%\adwcleaner\quarantine |
%programfiles%\panda security\panda security protection |
%desktop%\restored |
%sysdrive%\adwcleaner\quarantine\v1\20180424.160605 |
roboot64.exe |
fkabvesvsqgthlvmvodikjvdrfdimmqt.back |
ydeorvhgmfbcwofiowhkhvdozyrxzalr.back |
roboot64.exe#D5475221920302DD |
|
28.5% |
|
|
10.8% |
|
|
5.8% |
|
|
5.3% |
|
|
4.3% |
|
|
4.2% |
|
|
4.2% |
|
|
2.8% |
|
|
2.5% |
|
|
2.3% |
|
|
2.0% |
|
|
2.0% |
|
|
1.8% |
|
|
1.5% |
|
|
1.5% |
|
|
1.2% |
|
|
1.0% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.7% |
|
|
0.7% |
|
|
0.7% |
|
|
0.7% |
|
|
0.7% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
Windows 10 |
47.6% |
|
Windows 7 |
41.6% |
|
Windows 8.1 |
9.0% |
|
Windows 8 |
1.5% |
|
Windows Vista |
0.3% |
|
Analysis
Subsystem: |
Native |
PE Type: |
pe |
OS Bitness: |
64 |
Image Base: |
0x0000000100000000 |
Entry Address: |
0x0000247c |
Name |
Size of data |
MD5 |
.text |
9728 |
219fecd3cfda4d8b10045f836868dcf3 |
.data |
512 |
043c46095689123e1f5be96c109c2f46 |
.pdata |
512 |
522e7ece45fc23ef8ecf7d65ea5148e5 |
.rsrc |
1536 |
897db0f45a8e15165a9ee3089b2a5a0e |
.reloc |
512 |
4c69442f94342f01c9eecc224c99f9b1 |