How to remove play.exe
play.exe
The module play.exe has been detected as Trojan.Gen
File Details
Product Name: | WebZen mu main |
Company Name: | WebZen |
MD5: | 022fe2c94b1909f551430dbeb22e05db |
Size: | 19 MB |
First Published: | 2017-06-24 21:03:31 (7 years ago) |
Latest Published: | 2020-09-01 13:25:09 (4 years ago) |
Status: | Trojan.Gen (on last analysis) | |
Analysis Date: | 2020-09-01 13:25:09 (4 years ago) |
Overview
Signed By: | WEBZEN Inc. |
Status: | Invalid (digital signature could be stolen or file could be patched) |
Common Places:
%desktop%\wogs12final |
%profile%\downloads\wogs12full\wogs12full |
%desktop%\titanmu.net s12v2 |
%desktop%\mublitz s12 game client files\mublitz |
%profile%\downloads\newworldmu\newworldmu |
%desktop%\v0zmuonline-tiengviet(full)\v0zmuonline-tiengviet(full) |
%desktop% |
%desktop%\mupolska\globalmu s12ep1 |
%sysdrive%\games |
%sysdrive%\games\mux40 |
File Names:
main.exe |
play.exe |
Main.exe |
Geography:
24.6% | ||
17.5% | ||
7.0% | ||
7.0% | ||
7.0% | ||
5.3% | ||
5.3% | ||
3.5% | ||
3.5% | ||
3.5% | ||
3.5% | ||
3.5% | ||
1.8% | ||
1.8% | ||
1.8% | ||
1.8% | ||
1.8% |
OS Version:
Windows 7 | 49.1% | |
Windows 10 | 49.1% | |
Windows 8.1 | 1.8% |
Analysis
Subsystem: | Windows GUI |
PE Type: | pe |
OS Bitness: | 32 |
Image Base: | 0x00400000 |
Entry Address: | 0x00b7a4b4 |
PE Sections:
Name | Size of data | MD5 |
.text | 15629824 | 18404f3cd0a4f502a29ed9da4e356ac8 |
.rdata | 1925632 | c8feb049664840986400b4b2d0b96a45 |
.data | 190464 | 9ef417ad1003c959d95aa746ef57f304 |
.rsrc | 2862080 | 7286b9ffd88f80efa100ece11f9ce1d0 |
More information:
Download GridinSoft
Anti-Malware - Removal tool for play.exe