How to remove C501.exe
C501.exe
The module C501.exe has been detected as Ransom.STOP
File Details
| Product Name: | Latte |
| Company Name: | MagicWind |
| MD5: | 51c7e0efb85278b12512865fafb9f6dd |
| Size: | 798 KB |
| First Published: | 2023-06-03 23:51:30 (2 years ago) |
| Latest Published: | 2023-06-04 23:27:26 (2 years ago) |
| Status: | Ransom.STOP (on last analysis) | |
| Analysis Date: | 2023-06-04 23:27:26 (2 years ago) |
Common Places:
| %localappdata% |
| %temp% |
| %localappdata% |
| %temp% |
| %temp% |
| %temp% |
| %localappdata% |
| %temp% |
| %temp% |
| %localappdata% |
Geography:
| 62.5% | ||
| 18.8% | ||
| 18.8% |
OS Version:
| Windows 10 | 100.0% |
Analysis
| Subsystem: | Windows GUI |
| PE Type: | pe |
| OS Bitness: | 32 |
| Image Base: | 0x00400000 |
| Entry Address: | 0x00008dfe |
PE Sections:
| Name | Size of data | MD5 |
| .text | 105984 | b867d44ac86401ffb4a29371babe5c12 |
| .data | 599552 | f11e270c39875923f2ab1f7572f919e7 |
| .rsrc | 110592 | 9582c3f185e3303480da1663c594f062 |
More information:
Download GridinSoft
Anti-Malware - Removal tool for C501.exe