How to remove CoreSyncCustomHook.exe
- File Details
- Overview
- Analysis
CoreSyncCustomHook.exe
The module CoreSyncCustomHook.exe has been detected as Worm.Ramnit
File Details
Product Name: |
|
Company Name: |
|
MD5: |
cd9524d5b25a207be5f65f41c5a93a36 |
Size: |
1 MB |
First Published: |
2018-10-08 15:14:14 (5 years ago) |
Latest Published: |
2018-10-08 15:14:14 (5 years ago) |
Status: |
Worm.Ramnit (on last analysis) |
|
Analysis Date: |
2018-10-08 15:14:14 (5 years ago) |
%commondir%\adobe\coresyncextension |
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x00134000 |
Name |
Size of data |
MD5 |
.text |
1006080 |
f63094d322e688df7053666cb05736f0 |
.rdata |
172032 |
668e9d9d47060b81f6251bf73af9eb4f |
.data |
15872 |
005a1720090974511ae5b42f272ed4d6 |
.gfids |
2048 |
bfa5f8849fba564a5fd1979a5e2444c7 |
.tls |
512 |
1f354d76203061bfdd5a53dae48d5435 |
.rsrc |
2048 |
67996016f6e6e71b31ac27cf4aca5abc |
.reloc |
40960 |
381392357c779fa0b65123e208f5f4fb |
.text |
110592 |
ebd81cb2cd643d31767c7a54811587d6 |