How to remove PowerExpertNT.exe
- File Details
- Overview
- Analysis
PowerExpertNT.exe
The module PowerExpertNT.exe has been detected as Ransom.Sabsik
File Details
| Product Name: |
|
| Company Name: |
|
| MD5: |
102a9c6dfbd4bd3879659598b5c397a4 |
| Size: |
5 MB |
| First Published: |
2023-10-31 23:13:17 (2 years ago) |
| Latest Published: |
2024-07-22 23:00:59 (a year ago) |
| Status: |
Ransom.Sabsik (on last analysis) |
|
| Analysis Date: |
2024-07-22 23:00:59 (a year ago) |
Overview
| %temp% |
| %commonappdata% |
| %commonappdata% |
| %localappdata% |
| %temp% |
| %localappdata% |
| %commonappdata% |
| %commonappdata% |
| %commonappdata% |
| %localappdata% |
|
18.4% |
|
|
13.2% |
|
|
10.5% |
|
|
10.5% |
|
|
10.5% |
|
|
10.5% |
|
|
10.5% |
|
|
10.5% |
|
|
2.6% |
|
|
2.6% |
|
| Windows 10 |
97.4% |
|
| Windows 7 |
2.6% |
|
Analysis
| Subsystem: |
Windows GUI |
| PE Type: |
pe |
| OS Bitness: |
32 |
| Image Base: |
0x00400000 |
| Entry Address: |
0x007bb794 |
| Name |
Size of data |
MD5 |
| .text |
0 |
d41d8cd98f00b204e9800998ecf8427e |
| .rdata |
0 |
d41d8cd98f00b204e9800998ecf8427e |
| .data |
0 |
d41d8cd98f00b204e9800998ecf8427e |
| .vmp^-^0 |
0 |
d41d8cd98f00b204e9800998ecf8427e |
| .vmp^-^1 |
1536 |
93d5f973c52bdde88131ec82206da63f |
| .vmp^-^2 |
5266432 |
7bc491a682882331df75ec82994ed1db |
| .reloc |
7168 |
537fcf1f529016dcbb89dac3665eb3a5 |
| .rsrc |
263680 |
fab7352ac1da0cf63f38c2e9607bf9bb |