How to remove $RIQVRT5.exe
- File Details
- Overview
- Analysis
$RIQVRT5.exe
The module $RIQVRT5.exe has been detected as Worm.Ramnit
File Details
| Product Name: |
|
| Company Name: |
|
| MD5: |
8f7040c2cf29f68f95643e2a71bb6912 |
| Size: |
2 MB |
| First Published: |
2021-01-04 20:08:32 (4 years ago) |
| Latest Published: |
2021-01-04 20:08:32 (4 years ago) |
| Status: |
Worm.Ramnit (on last analysis) |
|
| Analysis Date: |
2021-01-04 20:08:32 (4 years ago) |
Analysis
| Subsystem: |
Windows GUI |
| PE Type: |
pe |
| OS Bitness: |
32 |
| Image Base: |
0x00400000 |
| Entry Address: |
0x003a5000 |
| Name |
Size of data |
MD5 |
| .text |
2260992 |
84a93a31ee09d5c3f4d0cd6f1994dad6 |
| .code |
49152 |
714283871818816d523fd026fbe742ac |
| .rdata |
221184 |
86854cd77eb739499a7623ac248c4331 |
| .data |
98304 |
4c9ad4c3caa9302636e8ea5a9c2e5e13 |
| .data2 |
4096 |
14dd83956e35597faff86a9d61f9f330 |
| .idata |
45056 |
ed35ed1c5d548c0a06e2591ccad6c4f8 |
| .rsrc |
16384 |
bfbe9a506e752cf8c2deefaef159057e |
| .text |
106496 |
ae666e57fbbc68293b1209af06b759a9 |