How to remove trz8001.tmp
- File Details
- Overview
- Analysis
trz8001.tmp
The module trz8001.tmp has been detected as Trojan.Agent
File Details
| MD5: |
f0881d5a7f75389deba3eff3f4df09ac |
| Size: |
232 KB |
| First Published: |
2017-07-18 23:06:44 (8 years ago) |
| Latest Published: |
2025-05-31 23:03:15 (7 months ago) |
| Status: |
Trojan.Agent (on last analysis) |
|
| Analysis Date: |
2025-05-31 23:03:15 (7 months ago) |
| %appdata%\ltdltd61\ea |
| %sysdrive%\windows.old\users\toshiba\appdata\local\temp\305576 |
| %sysdrive%\windows.old\users\toshiba\appdata\local\temp\2510001 |
| %sysdrive%\windows.old\users\toshiba\appdata\local\temp\312898 |
| %temp%\1317829 |
| %profile%\ocalservice\local settings\temp\1266698628 |
| %profile%\ocalservice\local settings\temp\1229191031 |
| %profile%\ocalservice\local settings\temp\1195433385 |
| %profile%\ocalservice\local settings\temp\1150596088 |
| %profile%\ocalservice\local settings\temp\1418631798 |
| tibe-2.dll |
| tibe-2.Vdll |
| trz6838.tmp |
| tibe-2.dll.quarantined |
| trz8001.tmp |
|
40.1% |
|
|
11.8% |
|
|
8.7% |
|
|
8.7% |
|
|
4.4% |
|
|
3.7% |
|
|
2.4% |
|
|
2.2% |
|
|
1.6% |
|
|
1.5% |
|
|
1.3% |
|
|
1.2% |
|
|
0.9% |
|
|
0.9% |
|
|
0.8% |
|
|
0.7% |
|
|
0.7% |
|
|
0.6% |
|
|
0.5% |
|
|
0.5% |
|
|
0.4% |
|
|
0.4% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
| Windows 7 |
85.2% |
|
| Windows 10 |
8.4% |
|
| Windows Server 2008 R2 |
3.1% |
|
| Windows XP |
1.2% |
|
| Windows 8.1 |
1.0% |
|
| Windows Server 2012 R2 |
0.4% |
|
| Windows Vista |
0.3% |
|
| Windows Server 2003 |
0.2% |
|
Analysis
| Subsystem: |
Windows GUI |
| PE Type: |
pe |
| OS Bitness: |
32 |
| Image Base: |
0x10000000 |
| Entry Address: |
0x0003263e |
| Name |
Size of data |
MD5 |
| .text |
203776 |
697c1cefc96b7c9e624169cd255becfa |
| .rdata |
23552 |
6a5ad6293b89abc232856bcbf81a5cb7 |
| .data |
5632 |
56b06e168bebe53c283cf90608252dd1 |
| .reloc |
3584 |
3c3c68800159ff4088983ff3318bdbc7 |