How to remove RecoverKeys.exe
- File Details
- Overview
- Analysis
RecoverKeys.exe
The module RecoverKeys.exe has been detected as Trojan.Wacatac
File Details
| Product Name: |
|
| Company Name: |
|
| MD5: |
0e0b027876dc809f325fa1b1142d9f7f |
| Size: |
11 MB |
| First Published: |
2020-06-17 09:15:58 (5 years ago) |
| Latest Published: |
2024-01-23 23:05:36 (2 years ago) |
| Status: |
Trojan.Wacatac (on last analysis) |
|
| Analysis Date: |
2024-01-23 23:05:36 (2 years ago) |
| %sysdrive%\installs\recover keys portable\philka.ru_recover_keys_enterprise_11.0.4.233\ncrecoverkeysportable\app |
| %sysdrive%\key + hesla soft\nc recoverkeys 11.0.4.233 portable cz\app |
| %desktop%\medicat.usb.v21.12\portableapps\recoverkeysportable\app |
Analysis
| Subsystem: |
Windows GUI |
| PE Type: |
pe |
| OS Bitness: |
32 |
| Image Base: |
0x00400000 |
| Entry Address: |
0x0136d5e6 |
| Name |
Size of data |
MD5 |
| .text |
0 |
00000000000000000000000000000000 |
| .itext |
0 |
00000000000000000000000000000000 |
| .data |
0 |
00000000000000000000000000000000 |
| .bss |
0 |
00000000000000000000000000000000 |
| .idata |
0 |
00000000000000000000000000000000 |
| .didata |
0 |
00000000000000000000000000000000 |
| .tls |
0 |
00000000000000000000000000000000 |
| .rdata |
0 |
00000000000000000000000000000000 |
| .vmp0 |
0 |
00000000000000000000000000000000 |
| .vmp1 |
11338752 |
7e5769d440aa65dbfa1c9e5ef87a88a2 |
| .rsrc |
356352 |
916ee705f3fd2e989e298b1745f53878 |