How to remove temp_mload.exe
- File Details
- Overview
- Analysis
temp_mload.exe
The module temp_mload.exe has been detected as General Threat
File Details
Product Name: |
|
Company Name: |
|
MD5: |
b864c557c4131578a9685c414003377d |
Size: |
2 MB |
First Published: |
2017-06-27 11:02:38 (7 years ago) |
Latest Published: |
2021-10-18 20:53:31 (3 years ago) |
Status: |
General Threat (on last analysis) |
|
Analysis Date: |
2021-10-18 20:53:31 (3 years ago) |
%profile%\downloads\mbot\mbot |
%desktop%\ailona\mbot |
%desktop%\mbot2\mbot |
%programfiles%\skype\phone |
%desktop%\badboys |
%desktop%\fingirdek |
%desktop%\turanlar |
%temp%\rar$dr00.188\mbot |
%temp%\rar$dr00.875\mbot |
%desktop%\mbot listesi\mbot |
mBotLoader.exe |
temp_mload.exe |
gtemp_mload.exe |
mBotLoader_xp_vista_7.exe |
mbotLoader.exe |
|
39.0% |
|
|
33.4% |
|
|
14.8% |
|
|
2.6% |
|
|
2.4% |
|
|
1.9% |
|
|
1.7% |
|
|
0.9% |
|
|
0.7% |
|
|
0.7% |
|
|
0.7% |
|
|
0.3% |
|
|
0.3% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
Windows 10 |
55.1% |
|
Windows 7 |
37.3% |
|
Windows 8 |
3.9% |
|
Windows 8.1 |
3.7% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x00001000 |
Name |
Size of data |
MD5 |
.text |
512 |
7c91e9bf16a66fc2801543a68310a633 |
.rdata |
512 |
23c2cfdf6c4d174df15f037768b5e3ca |
.main |
2520064 |
19ac45bf1551f24f1d86aca6b2a7035c |
.rsrc |
34304 |
b6dfb3582dd2455ef60171848db20a13 |