How to remove RoAR6uxlAR9OOIa77RcQiQYf.exe

RoAR6uxlAR9OOIa77RcQiQYf.exe

The module RoAR6uxlAR9OOIa77RcQiQYf.exe has been detected as Ransom.Wacatac

RoAR6uxlAR9OOIa77RcQiQYf.exe
Product Name:

dense_installation_with_plugin

MD5: 7e2bc6d413a3c4785c131b70bcd572a1
Size: 5 MB
First Published: 2023-11-18 23:03:52 (2 years ago)
Latest Published: 2023-11-19 23:04:53 (2 years ago)
Status: Ransom.Wacatac (on last analysis)
Analysis Date: 2023-11-19 23:04:53 (2 years ago)
Signed By: Tally Solutions Private Limited
Status: Invalid (digital signature could be stolen or file could be patched)
%profile%\pictures
%profile%\pictures
%profile%\pictures
66.7%
33.3%
Windows 10 100.0%
Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x005d4cae

PE Sections:

Name Size of data MD5
.text 6106624 1c042201ea2b373b56993b4c8920b316
.sdata 512 c74d93115f2733a0ce8a66482352081c
.rsrc 80384 7f6ca16c7329b28a89ceac0a27dad06e
.reloc 512 12e43a35f236dd0a72da5e73384850f1

More information:

Download GridinSoft Anti-Malware - Removal tool for RoAR6uxlAR9OOIa77RcQiQYf.exe