How to remove OSE.EXE
OSE.EXE
The module OSE.EXE has been detected as Virus.Neshta

File Details
MD5: | 8364677c293fdbdc1d485a227815f2b1 |
Size: | 182 KB |
First Published: | 2017-07-21 14:06:10 (7 years ago) |
Latest Published: | 2024-12-07 23:04:53 (6 months ago) |
Status: | Virus.Neshta (on last analysis) | |
Analysis Date: | 2024-12-07 23:04:53 (6 months ago) |
Common Places:
%sysdrive%\msocache\all users\{90120000-0030-0000-0000-0000000ff1ce}-c |
%sysdrive%\msocache\all users\{90120000-0018-0000-0000-0000000ff1ce}-c |
%commondir%\microsoft shared |
%sysdrive%\msocache\all users |
%sysdrive%\tool\office 2007\office 2007 |
%desktop%\nova pasta\nova pasta (3)\office 2007 - pt-br - phdowns |
%sysdrive%\office 2007 |
%profile%\downloads\ms office professional 2007 english v1014\en_office_professional_2007_x12-21440 |
%sysdrive%\dropbox\dropbox\visio 2007\ru_visioprofessional_12.0.4518.1022_bypass_ship_x86_cd |
%desktop%\visio 2007\ru_visioprofessional_12.0.4518.1022_bypass_ship_x86_cd |
File Names:
ose.exe |
OSE.EXE |
Geography:
31.7% | ||
12.7% | ||
9.5% | ||
7.9% | ||
6.3% | ||
4.8% | ||
3.2% | ||
3.2% | ||
3.2% | ||
3.2% | ||
1.6% | ||
1.6% | ||
1.6% | ||
1.6% | ||
1.6% | ||
1.6% | ||
1.6% | ||
1.6% | ||
1.6% |
OS Version:
Windows 7 | 73.4% | |
Windows 8.1 | 12.5% | |
Windows 10 | 7.8% | |
Windows Server 2012 R2 | 3.1% | |
Windows Server 2008 R2 | 1.6% | |
Windows XP | 1.6% |
Analysis
Subsystem: | Windows GUI |
PE Type: | pe |
OS Bitness: | 32 |
Image Base: | 0x00400000 |
Entry Address: | 0x000080e4 |
PE Sections:
Name | Size of data | MD5 |
CODE | 29696 | ca3464d4f08c9010e7ffa2fe3e890344 |
DATA | 1024 | 7ffc3168a7f3103634abdf3a768ed128 |
BSS | 0 | 00000000000000000000000000000000 |
.idata | 2560 | 6e7a45521bfca94f1e506361f70e7261 |
.tls | 0 | 00000000000000000000000000000000 |
.rdata | 512 | 7e6c0f4f4435abc870eb550d5072bad6 |
.reloc | 1536 | 16968c66d220638496d6b095f21de777 |
.rsrc | 5120 | 0bda792e1a4385a8c5dce49ce9bdec9e |
More information:
Download GridinSoft
Anti-Malware - Removal tool for OSE.EXE
