How to remove 295F.exe
295F.exe
The module 295F.exe has been detected as Ransom.Wacatac
File Details
| Product Name: | honeyed |
| Company Name: | overaction forerunning |
| MD5: | 624fe808cfc29dc2397e1614f1ab5644 |
| Size: | 227 KB |
| First Published: | 2022-05-19 23:11:57 (3 years ago) |
| Latest Published: | 2022-05-19 23:11:57 (3 years ago) |
| Status: | Ransom.Wacatac (on last analysis) | |
| Analysis Date: | 2022-05-19 23:11:57 (3 years ago) |
Overview
| Signed By: | Valve Corp. |
| Status: | Invalid (digital signature could be stolen or file could be patched) |
Common Places:
| %temp% |
Geography:
| United States | 100.0% |
OS Version:
| Windows 10 | 100.0% |
Analysis
| Subsystem: | Windows CUI |
| PE Type: | pe |
| OS Bitness: | 32 |
| Image Base: | 0x00400000 |
| Entry Address: | 0x00004425 |
PE Sections:
| Name | Size of data | MD5 |
| .text | 18432 | 672da5468e863b793d1178b094167015 |
| .rdata | 11264 | 53a81a777a142dc6e3024265bfe5191d |
| .data | 189952 | ab7bde901fef7f74f29f2830362eb0a2 |
| .rsrc | 1536 | c940a4bdad7333264c3d6d433f1c2920 |
| .reloc | 1536 | ad7e0c00f853b88e913dd2b84ce5b0f0 |
More information:
Download GridinSoft
Anti-Malware - Removal tool for 295F.exe