How to remove A0031300.EXE
- File Details
- Overview
- Analysis
A0031300.EXE
The module A0031300.EXE has been detected as Ransom.Exp
File Details
Company Name: |
|
MD5: |
a73ace8da558ff7aa7301eb88cfaa677 |
Size: |
360 KB |
First Published: |
2018-02-17 18:12:43 (6 years ago) |
Latest Published: |
2020-10-31 06:20:32 (4 years ago) |
Status: |
Ransom.Exp (on last analysis) |
|
Analysis Date: |
2020-10-31 06:20:32 (4 years ago) |
%sysdrive%\system volume information\_restore{4beab8e5-3e7b-4113-a13c-956c990378bd} |
%desktop%\#root\session 2\track 2\my disc \sotwear |
%sysdrive%\fra gammel seagate\ole jørgen bilde og ting |
%sysdrive%\fra gammel seagate\ole jørgen bilde og ting |
Windows 10 |
75.0% |
|
Windows 7 |
25.0% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x0000636d |
Name |
Size of data |
MD5 |
.text |
69632 |
8fb851976724bc50904206f849eec6f9 |
.rdata |
8192 |
c7cb593d8382d68e84809a8ebc097c48 |
.data |
8192 |
ea713a85c3390ab80cf072b34b2b4da1 |
.rsrc |
278528 |
cebd4c05daa0293ed488741a63f9512e |