How to remove 1889.exe

1889.exe

The module 1889.exe has been detected as Ransom.STOP

1889.exe

1889.exe is a Windows file recorded in the ThreatInfo database. It is associated with Pircuzar. The current detection status is Ransom.STOP, based on the latest analysis from 2024-03-18 23:02:23 (2 years ago).

If 1889.exe appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as Ransom.STOP.

Product Name: Pircuzar
MD5: fa0fdb300f7d2b2f4971908b19796c47
Size: 818 KB
First Published: 2024-03-18 23:02:23 (2 years ago)
Latest Published: 2024-03-18 23:02:23 (2 years ago)
Status: Ransom.STOP (on last analysis)
Analysis Date: 2024-03-18 23:02:23 (2 years ago)
%sysdrive%\windows.old\users\ik10\appdata\local

ThreatInfo has observed 1889.exe in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

100.0%

The strongest geographic signal for this file is Serbia with 100.0% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 100.0%

The most common operating system signal for 1889.exe is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

1889.exe is identified as pe for 32 systems. The subsystem is Windows GUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x0000b0f0

PE Sections:

Name Size of data MD5
.text 91136 b36609064a759f4e869e91e50dcb39a3
.data 665600 3fb18a37ce9b570b22910eaa74c3d82e
.idata 3072 393f01e0c11585b239f902983e6eacae
.yovur 1024 0f343b0931126a20f133d67c2b018a3b
.hira 6656 3c63825015aabd810674f44afac6d12b
.cet 1024 0f343b0931126a20f133d67c2b018a3b
.rsrc 68096 bde9ce884c36a824fbe8ffe113ec7e38

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information:

Download GridinSoft Anti-Malware - Removal tool for 1889.exe