How to remove pcrecpp-0.dll
- File Details
- Overview
- Analysis
pcrecpp-0.dll
The module pcrecpp-0.dll has been detected as Trojan.Agent
File Details
MD5: |
09836461312a3781af6e1298c6b2c249 |
Size: |
32 KB |
First Published: |
2017-07-18 23:06:47 (6 years ago) |
Latest Published: |
2024-03-23 23:02:47 (3 weeks ago) |
Status: |
Trojan.Agent (on last analysis) |
|
Analysis Date: |
2024-03-23 23:02:47 (3 weeks ago) |
%appdata%\ltdltd61\ea |
%appdata%\notifynotify82\ea |
%windir%\setup\fou |
%system%\mfen.exe |
%commonappdata%\rundll |
%windir%\system32 |
%commonappdata%\svhost |
%sysdrive%\$recycle.bin\s-1-5-21-2570348591-2767011175-3200952900-1016\$ro0c72t.rar\445\run\specials |
%temp%\5\rarsfx1 |
%temp%\5\rarsfx3 |
|
39.5% |
|
|
12.2% |
|
|
9.4% |
|
|
8.3% |
|
|
3.7% |
|
|
3.7% |
|
|
2.4% |
|
|
2.4% |
|
|
1.7% |
|
|
1.6% |
|
|
1.5% |
|
|
1.3% |
|
|
0.9% |
|
|
0.9% |
|
|
0.7% |
|
|
0.7% |
|
|
0.7% |
|
|
0.6% |
|
|
0.6% |
|
|
0.5% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
Windows 7 |
85.7% |
|
Windows 10 |
9.5% |
|
Windows Server 2008 R2 |
2.4% |
|
Windows 8.1 |
1.0% |
|
Windows XP |
0.7% |
|
Windows Server 2012 R2 |
0.3% |
|
Windows Vista |
0.3% |
|
Windows Web Server 2008 R2 |
0.1% |
|
Windows Server 2003 |
0.1% |
|
Windows 8 |
0.1% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x10000000 |
Entry Address: |
0x00003e3e |
Name |
Size of data |
MD5 |
.text |
13824 |
9cf59a4456e639300552bd58e8288d70 |
.rdata |
14848 |
dd41b56ae56c1127dee7ff4984726740 |
.data |
1024 |
8e03e751518dbd9cc29b7830aec2cfc5 |
.reloc |
2048 |
25bcf41dab6da0330985ba6e12b468ae |