How to remove PowerExpertNT.exe
- File Details
- Overview
- Analysis
PowerExpertNT.exe
The module PowerExpertNT.exe has been detected as Ransom.Sabsik
File Details
Product Name: |
|
Company Name: |
|
MD5: |
102a9c6dfbd4bd3879659598b5c397a4 |
Size: |
5 MB |
First Published: |
2023-10-31 23:13:17 (2 years ago) |
Latest Published: |
2024-07-22 23:00:59 (a year ago) |
Status: |
Ransom.Sabsik (on last analysis) |
|
Analysis Date: |
2024-07-22 23:00:59 (a year ago) |
Overview
%temp% |
%commonappdata% |
%commonappdata% |
%localappdata% |
%temp% |
%localappdata% |
%commonappdata% |
%commonappdata% |
%commonappdata% |
%localappdata% |
|
18.4% |
|
|
13.2% |
|
|
10.5% |
|
|
10.5% |
|
|
10.5% |
|
|
10.5% |
|
|
10.5% |
|
|
10.5% |
|
|
2.6% |
|
|
2.6% |
|
Windows 10 |
97.4% |
|
Windows 7 |
2.6% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x007bb794 |
Name |
Size of data |
MD5 |
.text |
0 |
d41d8cd98f00b204e9800998ecf8427e |
.rdata |
0 |
d41d8cd98f00b204e9800998ecf8427e |
.data |
0 |
d41d8cd98f00b204e9800998ecf8427e |
.vmp^-^0 |
0 |
d41d8cd98f00b204e9800998ecf8427e |
.vmp^-^1 |
1536 |
93d5f973c52bdde88131ec82206da63f |
.vmp^-^2 |
5266432 |
7bc491a682882331df75ec82994ed1db |
.reloc |
7168 |
537fcf1f529016dcbb89dac3665eb3a5 |
.rsrc |
263680 |
fab7352ac1da0cf63f38c2e9607bf9bb |