How to remove RemoveWAT.exe
- File Details
- Overview
- Analysis
RemoveWAT.exe
The module RemoveWAT.exe has been detected as Hack.KMS
File Details
Product Name: |
|
Company Name: |
|
MD5: |
fb6f86c55d4ca58929f65eeb6a8417d9 |
Size: |
1 MB |
First Published: |
2017-10-27 04:06:31 (6 years ago) |
Latest Published: |
2020-10-29 22:10:10 (3 years ago) |
Status: |
Hack.KMS (on last analysis) |
|
Analysis Date: |
2020-10-29 22:10:10 (3 years ago) |
%desktop%\extra\activation.adm.2011\licence x32.x64\removewattesté x32 |
%sysdrive%\programs\активатор 7\windows_7_loader |
%sysdrive%\programs\активатор 7\windows_7_loader.rar\windows_7_loader |
%desktop%\extra\activation.adm.2011\licence x32.x64 |
%sysdrive%\soft |
%sysdrive%\soufiane stu\extra\activation.adm.2011\licence x32.x64\removewattesté x32 |
%sysdrive%\soufiane stu\extra\activation.adm.2011\licence x32.x64 |
%sysdrive%\برامج\new folder\serials |
%sysdrive%\برامج\new folder (10)\serials |
%sysdrive% |
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x0010c62e |
MVID: |
ecbbb00a-6188-4a40-87c6-3b125961c416 |
Typelib ID: |
0e768eb8-c71c-4b52-bea8-92e4e837be70 |
Name |
Size of data |
MD5 |
.text |
1091584 |
8aa4d709cbfb247811afc7830d34deef |
.sdata |
512 |
cca1632b0a6705e9ed5958a118113fc0 |
.rsrc |
102400 |
2e014c302c3c3b131d6f18e97420824a |
.reloc |
512 |
404e2febf2e36fb58cece8e9f25fb555 |