How to remove shutdowntime.exe
- File Details
- Overview
- Analysis
shutdowntime.exe
The module shutdowntime.exe has been detected as Adware.Agent
File Details
Product Name: |
|
MD5: |
f9d1bb4a62197e1351689b0718b866ca |
Size: |
89 KB |
First Published: |
2017-08-11 13:09:04 (7 years ago) |
Latest Published: |
2021-01-09 03:07:24 (4 years ago) |
Status: |
Adware.Agent (on last analysis) |
|
Analysis Date: |
2021-01-09 03:07:24 (4 years ago) |
%programfiles%\shutdowntime |
%sysdrive%\adwcleaner\quarantine\zmrf6ci6nx |
%sysdrive%\$recycle.bin\s-1-5-21-3828551381-2779901327-3341855924-1000\$rh6lttk |
%sysdrive%\adwcleaner\quarantine\rywtiizs2t |
%sysdrive%\adwcleaner\quarantine\x3cf3ednhm |
%sysdrive%\system volume information\_restore{fd722be8-f37f-4270-80db-c5db4f9e38c6}\rp19 |
%sysdrive%\adwcleaner\quarantine\smlaztxc1o |
%sysdrive%\adwcleaner\quarantine\gxix4a2dre |
%programfiles% |
%sysdrive%\adwcleaner\quarantine |
ShutdownTime.exe |
shutdowntime.exe |
ShutdownTime.exe.quarantined |
A0008807.exe |
unp159771566.tmp |
ShutdownTime.html |
$RZXS0L9.exe |
$R1CJOL7.exe |
$RQ8IMD1.exe |
007323.EXE |
ShutdownTime_IObitDel.exe |
$R3EP8NU.exe |
ShutdownTime - Copy.exe |
|
12.1% |
|
|
8.5% |
|
|
7.9% |
|
|
4.4% |
|
|
4.2% |
|
|
3.4% |
|
|
3.2% |
|
|
3.1% |
|
|
3.1% |
|
|
2.8% |
|
|
2.7% |
|
|
2.5% |
|
|
2.0% |
|
|
1.8% |
|
|
1.7% |
|
|
1.6% |
|
|
1.5% |
|
|
1.3% |
|
|
1.3% |
|
|
1.2% |
|
|
1.2% |
|
|
1.2% |
|
|
1.1% |
|
|
1.0% |
|
|
1.0% |
|
|
1.0% |
|
|
1.0% |
|
|
0.9% |
|
|
0.9% |
|
|
0.8% |
|
|
0.8% |
|
|
0.7% |
|
|
0.7% |
|
|
0.6% |
|
|
0.6% |
|
|
0.5% |
|
|
0.5% |
|
|
0.5% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
Windows 10 |
70.0% |
|
Windows 7 |
22.5% |
|
Windows 8.1 |
5.8% |
|
Windows 8 |
1.1% |
|
Windows XP |
0.5% |
|
Windows Vista |
0.1% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x00017a32 |
MVID: |
f4869a60-4651-42b2-8c37-d3911f8fb47c |
Typelib ID: |
17d78b8e-8402-4e23-8c8f-27810b33f10e |
Name |
Size of data |
MD5 |
.text |
89088 |
06bb7a3c5fe626c30e12a740d76cbb37 |
.rsrc |
1536 |
a08c1dcb09270aaee475e38e816b5b47 |
.reloc |
512 |
2fd5c90a165d1fa83124a89918ef7f59 |