How to remove A0091017.exe
- File Details
- Overview
- Analysis
A0091017.exe
The module A0091017.exe has been detected as Worm.Ramnit
File Details
Product Name: |
|
Company Name: |
|
MD5: |
1784cc269e3461a93db540949b2e0755 |
Size: |
3 MB |
First Published: |
2018-04-15 08:11:27 (6 years ago) |
Latest Published: |
2018-04-15 08:11:27 (6 years ago) |
Status: |
Worm.Ramnit (on last analysis) |
|
Analysis Date: |
2018-04-15 08:11:27 (6 years ago) |
%sysdrive%\system volume information\_restore{600fc670-f159-4224-88db-329b87d563a9} |
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x003e8000 |
Name |
Size of data |
MD5 |
.text |
2398208 |
b3b4fc0f8dba24c71ce24ca8583de794 |
.data |
136704 |
6e7dc98a718e96d9efc06296d7612099 |
.tls |
512 |
bf619eac0cdf3f68d496ea9344137e8b |
.rdata |
512 |
b1e8dac62f1c61528950076e941a9e75 |
.idata |
15872 |
98c13c2b9c38ce157caf9fb96d717652 |
.edata |
236544 |
b6df86f6303a494a907c105d6e5338df |
.rsrc |
921600 |
4a3fb0803901b56bb19d17c29d4b9ab1 |
.vmp0 |
131584 |
f823877527bcad1a6fce120ba8d8ac63 |
.vmp1 |
23552 |
5369d0c3c4eccf435a692d3b702131de |
.reloc |
131072 |
08baca8504dc6acf3de34365aba747b8 |
.text |
166400 |
e46f47ccf66ccbf0f3fe413dbf59653c |