How to remove RemoveWAT.exe
- File Details
- Overview
- Analysis
RemoveWAT.exe
The module RemoveWAT.exe has been detected as General Threat
File Details
Product Name: |
|
MD5: |
1dae1764763eaa5ad14c75eb80f246e1 |
Size: |
1 MB |
First Published: |
2017-05-25 05:04:24 (6 years ago) |
Latest Published: |
2022-05-09 23:57:39 (2 years ago) |
Status: |
General Threat (on last analysis) |
|
Analysis Date: |
2022-05-09 23:57:39 (2 years ago) |
%windir%\setup\scripts |
%desktop%\程式檔\xmediarecode\永久啟用windows_7破解程式\永久啟用windows_7破解程式 |
%desktop%\shortcuts\new windows 7 activator [2010] |
%sysdrive%\system volume information\systemrestore\frstaging\users\paolo\desktop |
%temp%\rar$ex00.730 |
%temp%\rar$ex01.585 |
%desktop%\moje dokumenty\!!! windows.loader.v2.2.2-daz |
%profile%\google drive\new windows 7 activator [2010].rar |
%sysdrive%\$recycle.bin\s-1-5-21-1923013811-3152749515-4216600900-1000 |
%profile%\iska\asztal\instál progik\vindows 7 aktiválók\new windows 7 activator [2010] |
RemoveWAT (2).exe |
RemoveWAT.exe |
REMOVEWAT.EXE |
$RLVLZ2R.exe |
$RQQKRCL.exe |
RemoveWAT |
RemoveWAT 2.1.exe |
$RKBVZV8.exe |
Ativador do Windows 7 depois de reiniciar.exe |
[www.fisierulmeu.ro] RemoveWAT pentru licenta la windows 7.exe |
removewat.exe |
RemoveWAT 2.1_www.downsforyou.org.exe |
RemoveWAT_21 (Apply a New Crack).exe |
|
20.4% |
|
|
12.9% |
|
|
7.9% |
|
|
5.8% |
|
|
5.4% |
|
|
3.3% |
|
|
3.3% |
|
|
2.9% |
|
|
2.5% |
|
|
2.5% |
|
|
2.5% |
|
|
2.1% |
|
|
2.1% |
|
|
1.7% |
|
|
1.7% |
|
|
1.7% |
|
|
1.3% |
|
|
1.3% |
|
|
1.3% |
|
|
1.3% |
|
|
1.3% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.8% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
Windows 7 |
65.3% |
|
Windows 10 |
30.6% |
|
Windows 8.1 |
2.5% |
|
Windows Server 2012 |
0.8% |
|
Windows Vista |
0.4% |
|
Windows XP |
0.4% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x0010cbce |
MVID: |
ae7bc7cd-d8a3-4eb3-adc4-4d7cd54ab783 |
Typelib ID: |
0e768eb8-c71c-4b52-bea8-92e4e837be70 |
Name |
Size of data |
MD5 |
.text |
1092608 |
efa19c8e3c760df8abb40aeebe69f48f |
.sdata |
512 |
936c6edc07dcb5ae535a05bdc2afb929 |
.rsrc |
102400 |
9cef3076d0e1b56bb1a5a2e526779aad |
.reloc |
512 |
12b59b51ba340e89708366495abccb28 |