How to remove 4.exe

4.exe

The module 4.exe has been detected as Virtool.Passview

4.exe
Product Name:

Protected Storage PassView

Company Name:

NirSoft

MD5: 35861f4ea9a8ecb6c357bdb91b7df804
Size: 51 KB
First Published: 2017-05-22 11:23:25 (8 years ago)
Latest Published: 2021-03-25 21:46:22 (4 years ago)
Status: Virtool.Passview (on last analysis)
Analysis Date: 2021-03-25 21:46:22 (4 years ago)
%desktop%\lock\security\password finders
%desktop%\lock\001 a my tools\password finders
%profile%\downloads\outils informatique\gegeek toolkit\forensics\protectedstorageview
%profile%\downloads\outils informatique\gegeek toolkit\recovery\protectedstoragepassview
%profile%\downloads\outils informatique\gegeek toolkit\wsccportable\nirsoft utilities
%localappdata%\temp
%sysdrive%\misc\nirsoft tools\passwordrecovery
%sysdrive%\carboncs v1.1\hack facebook
%desktop%\forensik\dart @amp; deft\dart\dart\apps\passwordrecovery
%desktop%\xd\..3\usb hack
pspv.exe
4.exe
Netherlands 10.1%
Russia 7.6%
France 6.3%
Australia 5.1%
India 5.1%
Taiwan 5.1%
United States 5.1%
Switzerland 5.1%
Ukraine 3.8%
Hong Kong 3.8%
Belgium 3.8%
United Arab Emirates 3.8%
Italy 2.5%
Serbia 2.5%
United Kingdom 2.5%
Mexico 2.5%
Algeria 1.3%
Czech Republic 1.3%
Thailand 1.3%
Germany 1.3%
Tunisia 1.3%
Brazil 1.3%
Egypt 1.3%
Kyrgyzstan 1.3%
Puerto Rico 1.3%
Slovakia 1.3%
Peru 1.3%
Iran 1.3%
Poland 1.3%
South Korea 1.3%
Argentina 1.3%
Vietnam 1.3%
Nepal 1.3%
Colombia 1.3%
Croatia 1.3%
Spain 1.3%
Windows 10 62.0%
Windows 7 26.6%
Windows 8.1 6.3%
Windows Server 2003 2.5%
Windows Server 2012 R2 2.5%
Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x000075af

PE Sections:

Name Size of data MD5
.text 27136 59fbf7679e1047004e70db2fb2daa21b
.rdata 5632 d0a0b1b9c32bc0785db4500ff692f0ac
.data 3584 21a2907747e9110480cdc33625539c75
.rsrc 15360 df009447a4c1fafbedb21d2f6b8007d8

More information:

Download GridinSoft Anti-Malware - Removal tool for 4.exe
­