How to remove pageant.exe
- File Details
- Overview
- Analysis
pageant.exe
The module pageant.exe has been detected as Trojan.Emotet
File Details
Product Name: |
|
Company Name: |
|
MD5: |
61c5fe6fe1e387e210cd5ccd2027b205 |
Size: |
306 KB |
First Published: |
2018-08-03 13:07:19 (6 years ago) |
Latest Published: |
2018-08-07 04:12:26 (6 years ago) |
Status: |
Trojan.Emotet (on last analysis) |
|
Analysis Date: |
2018-08-07 04:12:26 (6 years ago) |
Overview
%programfiles% |
%programfiles%\wscc3\other utilities |
%sysdrive% |
|
22.0% |
|
|
17.1% |
|
|
7.3% |
|
|
4.9% |
|
|
4.9% |
|
|
4.9% |
|
|
4.9% |
|
|
4.9% |
|
|
2.4% |
|
|
2.4% |
|
|
2.4% |
|
|
2.4% |
|
|
2.4% |
|
|
2.4% |
|
|
2.4% |
|
|
2.4% |
|
|
2.4% |
|
|
2.4% |
|
|
2.4% |
|
|
2.4% |
|
Windows 10 |
70.5% |
|
Windows 7 |
25.0% |
|
Windows 8.1 |
4.5% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
64 |
Image Base: |
0x0000000140000000 |
Entry Address: |
0x000355a4 |
Name |
Size of data |
MD5 |
.00cfg |
512 |
585cbe37567670ad4bf1dc312b0575e2 |
.rdata |
62976 |
a0aa708e40caa070bb96d3e67f2e6438 |
.bss |
0 |
00000000000000000000000000000000 |
.data |
3072 |
8e36875a6e7159bb4712f920cc235827 |
.gfids |
512 |
14effd8aba101fccd0b12b4343d0e2cf |
.pdata |
9216 |
513c8f653348532554564e8cdcdb28f0 |
.rsrc |
8704 |
02b2927b159cf0b68772311cf2789782 |
.text |
195584 |
12e0425ce6e638c42f42d35c5a9241b6 |
.xdata |
11776 |
09708da6918aedb70de557197edb1ee3 |
.idata |
5632 |
834b170a1a14b5a6e8ca4b111c318852 |
.reloc |
2560 |
1c53d79bbad47c8ad03ed1493ab9f1a0 |