How to remove rs-recover64.exe
- File Details
- Overview
- Analysis
rs-recover64.exe
The module rs-recover64.exe has been detected as PUP.Gen
File Details
Product Name: |
|
Company Name: |
|
MD5: |
54586e5a79040cd92e56a9371b57c55d |
Size: |
3 MB |
First Published: |
2017-08-17 00:18:27 (6 years ago) |
Latest Published: |
2020-10-31 03:05:54 (3 years ago) |
Status: |
PUP.Gen (on last analysis) |
|
Analysis Date: |
2020-10-31 03:05:54 (3 years ago) |
Overview
%programfiles%\remo recover 4.0\64 |
%programfiles%\remo recover 4.0 |
%temp% |
%programfiles%\remo recover 4.0 |
%programfiles%\remo recover 4.0 |
%sysdrive%\4-7-2012\remo recover 4.0 |
%temp% |
%programfiles%\remo recover 4.0 |
%programfiles%\remo recover 4.0 |
%programfiles%\remo recover 4.0 |
rs-recover64.exe |
IUTemp.$$$ |
|
17.4% |
|
|
10.9% |
|
|
8.7% |
|
|
6.5% |
|
|
6.5% |
|
|
4.3% |
|
|
4.3% |
|
|
4.3% |
|
|
4.3% |
|
|
4.3% |
|
|
2.2% |
|
|
2.2% |
|
|
2.2% |
|
|
2.2% |
|
|
2.2% |
|
|
2.2% |
|
|
2.2% |
|
|
2.2% |
|
|
2.2% |
|
|
2.2% |
|
|
2.2% |
|
|
2.2% |
|
|
2.2% |
|
Windows 10 |
60.9% |
|
Windows 7 |
28.3% |
|
Windows 8.1 |
8.7% |
|
Windows XP |
2.2% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
64 |
Image Base: |
0x0000000140000000 |
Entry Address: |
0x003bf3f4 |
Name |
Size of data |
MD5 |
.text |
0 |
00000000000000000000000000000000 |
.rdata |
0 |
00000000000000000000000000000000 |
.data |
0 |
00000000000000000000000000000000 |
.pdata |
0 |
00000000000000000000000000000000 |
.reloc |
0 |
00000000000000000000000000000000 |
.text1 |
729088 |
5f65eb77c61ddb16da2de9449af1a8bb |
.adata |
4096 |
e2ae1302b399b533c2965fce9f0ab03b |
.data1 |
237568 |
a60bc34437a30ef99cc814fe4c8865e5 |
.pdata1 |
53248 |
f7f4897b1aa00c612db1f64c1bc879be |
.reloc1 |
8192 |
9cdf82b5dd5db50318662e59faead4e7 |
.pdata2 |
1769472 |
95e2cf6aca71996b6c0b0ca0a91076f6 |
.rsrc |
540672 |
c565fa2ec3b918b2f050e0aab102b7cc |