How to remove A0019455.exe
- File Details
- Overview
- Analysis
A0019455.exe
The module A0019455.exe has been detected as Worm.Ramnit
File Details
Product Name: |
|
Company Name: |
|
MD5: |
13c43b2b1ab4cc5c186842467849fb2d |
Size: |
3 MB |
First Published: |
2018-04-15 08:11:30 (6 years ago) |
Latest Published: |
2018-04-15 08:11:30 (6 years ago) |
Status: |
Worm.Ramnit (on last analysis) |
|
Analysis Date: |
2018-04-15 08:11:30 (6 years ago) |
%sysdrive%\system volume information\_restore{ee9e659f-b0dc-4227-95c9-1c7ccb8918df} |
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x003c9000 |
Name |
Size of data |
MD5 |
.text |
2386432 |
8ca6bd5776b55d0869d4bf5dbecf997c |
.data |
134656 |
52cf06530cac823b929133db2e214832 |
.tls |
512 |
bf619eac0cdf3f68d496ea9344137e8b |
.rdata |
512 |
d2d088383abe6dbfacddd7d5472418ea |
.idata |
15872 |
114a388bec4636b7e5d2803e84770b69 |
.edata |
236544 |
3661125bdbb0b3e5f6db677abfbed5ec |
.rsrc |
848896 |
c26db3f67ddeeb8a8ce396f497ddba64 |
.vmp0 |
130560 |
3ec16b06fbd091153bd769d576ddcafa |
.vmp1 |
18944 |
b724cab6368a55758c5a9c76c3b15bff |
.reloc |
130560 |
d93e3079a3f52296d3edf005dc36ba4b |
.text |
166400 |
0d3e9b2254dca63a096e153fd764cb3c |