How to remove ms.exe
ms.exe
The module ms.exe has been detected as Adware.OxyPumper
File Details
Product Name: | VideoBox Shortcut Installer |
Company Name: | VideoBox |
MD5: | 7663152489b1adb8cbe410c154722c92 |
Size: | 680 KB |
First Published: | 2017-06-13 19:08:12 (7 years ago) |
Latest Published: | 2018-08-30 05:02:29 (6 years ago) |
Status: | Adware.OxyPumper (on last analysis) | |
Analysis Date: | 2018-08-30 05:02:29 (6 years ago) |
Common Places:
%localappdata%\temp |
%sysdrive%\$recycle.bin\s-1-5-21-1595860782-1596682618-2454751602-1001\$ryt46ov\alfre\appdata\local\temp |
%temp% |
Geography:
31.5% | ||
25.9% | ||
11.1% | ||
5.6% | ||
3.7% | ||
3.7% | ||
3.7% | ||
3.7% | ||
3.7% | ||
1.9% | ||
1.9% | ||
1.9% | ||
1.9% |
OS Version:
Windows 7 | 50.0% | |
Windows 10 | 42.6% | |
Windows 8.1 | 7.4% |
Analysis
Subsystem: | Windows GUI |
PE Type: | pe |
OS Bitness: | 32 |
Image Base: | 0x00400000 |
Entry Address: | 0x000113bc |
PE Sections:
Name | Size of data | MD5 |
.text | 61952 | 1a600bbd86f701d3e6b2978b57906082 |
.itext | 3072 | 0b6f227afa44fd825f60bccacb9073bf |
.data | 3584 | da9cb156b6104ba552cb70804b8a50a3 |
.bss | 0 | 00000000000000000000000000000000 |
.idata | 3584 | 93d91a2b90e60bd758fc0c4908856ae1 |
.tls | 0 | 00000000000000000000000000000000 |
.rdata | 512 | 3dffc444ccc131c9dcee18db49ee6403 |
.rsrc | 45568 | e781e950b2707e6728e9f182b9f1494a |
More information:
Download GridinSoft
Anti-Malware - Removal tool for ms.exe