How to remove webcompanion.exe
- File Details
- Overview
- Analysis
webcompanion.exe
The module webcompanion.exe has been detected as PUP.WebCompanion
File Details
| MD5: |
3f6e9f8ce4c3fbd20768c9c12a98be5e |
| Size: |
1 MB |
| First Published: |
2017-05-22 11:16:48 (8 years ago) |
| Latest Published: |
2021-02-25 04:04:27 (4 years ago) |
| Status: |
PUP.WebCompanion (on last analysis) |
|
| Analysis Date: |
2021-02-25 04:04:27 (4 years ago) |
Overview
| %programfiles%\lavasoft\web companion\application |
| %sysdrive%\adwcleaner\quarantine\files\amvbdtwlmdislrqvgydikarceodksoym\application |
| %sysdrive%\adwcleaner\quarantine\files\hampfadcswqsrrdoktgzlwefjamplozh\application |
| %sysdrive%\adwcleaner\quarantine\files\uabeftksyfoziuzybzhgagujlrqyrscc\application |
| %sysdrive%\windows.old\program files (x86)\lavasoft\web companion\application |
| %windir%\temp\webcompanion.zip\application |
| %sysdrive%\adwcleaner\quarantine\files\hrbjrtikwseyytaizoeqvsedzeacdxuq\application |
| %temp%\webcompanion.zip\application |
| %sysdrive%\windows.old\program files\lavasoft\web companion\application |
| %sysdrive%\windows.old\users\user\appdata\local\temp\webcompanion.zip\application |
| WebCompanion.exe |
| webcompanion.exe |
|
15.5% |
|
|
10.3% |
|
|
6.9% |
|
|
6.9% |
|
|
5.2% |
|
|
3.4% |
|
|
3.4% |
|
|
3.4% |
|
|
3.4% |
|
|
3.4% |
|
|
3.4% |
|
|
3.4% |
|
|
3.4% |
|
|
3.4% |
|
|
1.7% |
|
|
1.7% |
|
|
1.7% |
|
|
1.7% |
|
|
1.7% |
|
|
1.7% |
|
|
1.7% |
|
|
1.7% |
|
|
1.7% |
|
|
1.7% |
|
|
1.7% |
|
|
1.7% |
|
|
1.7% |
|
|
1.7% |
|
| Windows 7 |
46.6% |
|
| Windows 10 |
37.9% |
|
| Windows 8.1 |
8.6% |
|
| Windows XP |
5.2% |
|
| Windows 8 |
1.7% |
|
Analysis
| Subsystem: |
Windows GUI |
| PE Type: |
pe |
| OS Bitness: |
32 |
| Image Base: |
0x00400000 |
| Entry Address: |
0x00162764 |
| MVID: |
65039b41-cbb0-45d7-b869-27666a47c96e |
| Name |
Size of data |
MD5 |
| .text |
1443840 |
dffbe1bed3533f0fd4f59eec767d7d07 |
| .rsrc |
29184 |
b6154a9146bbe6c59c70347f9feeea05 |
| .reloc |
512 |
f9b7cf89eddefe049d39782cb9c82175 |