How to remove Booking.exe
- File Details
- Overview
- Analysis
Booking.exe
The module Booking.exe has been detected as Worm.Ramnit
File Details
Product Name: |
|
Company Name: |
|
MD5: |
c82db2894dcd9b1d857edeba4641f7a2 |
Size: |
54 MB |
First Published: |
2017-08-09 00:06:56 (7 years ago) |
Latest Published: |
2017-08-09 00:06:56 (7 years ago) |
Status: |
Worm.Ramnit (on last analysis) |
|
Analysis Date: |
2017-08-09 00:06:56 (7 years ago) |
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x036f1000 |
Name |
Size of data |
MD5 |
.text |
45607936 |
6520d4e09f1bd320ab3f90a9687486ec |
.rdata |
8952320 |
d153931c759c2e4cdb7a964cf10cf116 |
.data |
468480 |
99205a4f04e3bfc5a1e26a54f06cff2d |
.tls |
512 |
9efa43af7b1faae15ffbd428d0485819 |
.rodata |
3584 |
44fd3d670ab21dde911bd8b33886e642 |
.gfids |
3072 |
95c9eeaa121c68ce011e09fe616cb57e |
_RDATA |
512 |
541ae312af8f5981a726b33a1eae1f6e |
.rsrc |
431104 |
e10192230bf74972a24f4cf5485662f2 |
.reloc |
1761792 |
d0b278c8a650f4f9d921e9d6c5ade338 |
.text |
131584 |
3e2f010c2c0b08d3a96242a2c8fed9a0 |