How to remove wrar550 (1).exe
- File Details
- Overview
- Analysis
wrar550 (1).exe
The module wrar550 (1).exe has been detected as Adware.Downloader
File Details
Product Name: |
|
Company Name: |
|
MD5: |
a1a57219d8cc7f0b7cc22d1a43147c65 |
Size: |
2 MB |
First Published: |
2018-04-23 13:06:05 (6 years ago) |
Latest Published: |
2020-11-24 11:43:58 (4 years ago) |
Status: |
Adware.Downloader (on last analysis) |
|
Analysis Date: |
2020-11-24 11:43:58 (4 years ago) |
Overview
%profile% |
%sysdrive% |
%profile%\downloads |
%profile%\ecep\belgelerim |
%sysdrive%\programs |
%sysdrive%\$recycle.bin |
%sysdrive%\downloads |
%profile%\downloads\programs |
%temp% |
%localappdata%\microsoft\windows\temporary internet files\content.ie5 |
wrar550.exe |
wrar550 (1).exe |
$RF4NS7R.exe |
$RH4XU7D.exe |
$RCJ27WT.exe |
$RMSN2KR.exe |
A0146285.exe |
wrar550 32.exe |
Russia |
20.0% |
|
Thailand |
9.6% |
|
Vietnam |
8.5% |
|
United States |
6.5% |
|
India |
5.8% |
|
Turkey |
4.6% |
|
Indonesia |
4.2% |
|
Ukraine |
3.8% |
|
Philippines |
3.8% |
|
Egypt |
3.8% |
|
Brunei |
3.1% |
|
Netherlands |
2.3% |
|
Saudi Arabia |
1.5% |
|
United Kingdom |
1.2% |
|
Romania |
1.2% |
|
Italy |
1.2% |
|
Sri Lanka |
1.2% |
|
Belarus |
1.2% |
|
Canada |
1.2% |
|
Israel |
1.2% |
|
Belgium |
1.2% |
|
Australia |
0.8% |
|
Malaysia |
0.8% |
|
Algeria |
0.8% |
|
Sweden |
0.8% |
|
Pakistan |
0.8% |
|
Lithuania |
0.8% |
|
Tanzania |
0.8% |
|
Iraq |
0.4% |
|
Germany |
0.4% |
|
Iran |
0.4% |
|
Seychelles |
0.4% |
|
Singapore |
0.4% |
|
Bangladesh |
0.4% |
|
Bulgaria |
0.4% |
|
South Korea |
0.4% |
|
Poland |
0.4% |
|
China |
0.4% |
|
Norway |
0.4% |
|
Spain |
0.4% |
|
South Africa |
0.4% |
|
Croatia |
0.4% |
|
Mauritius |
0.4% |
|
Latvia |
0.4% |
|
Taiwan |
0.4% |
|
Kazakhstan |
0.4% |
|
Saint Kitts and Nevis |
0.4% |
|
Japan |
0.4% |
|
Windows 10 |
67.3% |
|
Windows 7 |
23.1% |
|
Windows 8.1 |
6.5% |
|
Windows XP |
1.5% |
|
Windows 8 |
1.2% |
|
Windows Vista |
0.4% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x0000aa98 |
Name |
Size of data |
MD5 |
CODE |
41472 |
b7ea439d9c6d5ec722056c9243fb3054 |
DATA |
1024 |
9b2268ed5360951559d8041925d025fb |
BSS |
0 |
00000000000000000000000000000000 |
.idata |
2560 |
df5f31e62e05c787fd29eed7071bf556 |
.tls |
0 |
00000000000000000000000000000000 |
.rdata |
512 |
14dfa4128117e7f94fe2f8d7dea374a0 |
.reloc |
0 |
00000000000000000000000000000000 |
.rsrc |
11264 |
37d5790df1280d8ffbcaa1f0ba547c5e |