How to remove SETUP32.EXE

SETUP32.EXE

The module SETUP32.EXE has been detected as Worm.Ramnit

SETUP32.EXE
Product Name:

Corel Setup Wizard

Company Name:

Corel Corporation

MD5: bdb773e433c67c218d717e562c0e9e5c
Size: 1 MB
First Published: 2018-05-24 11:07:33 (6 years ago)
Latest Published: 2018-05-24 11:07:33 (6 years ago)
Status: Worm.Ramnit (on last analysis)
Analysis Date: 2018-05-24 11:07:33 (6 years ago)
%sysdrive%\software
100.0%
Windows 7 100.0%
Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x0013d000

PE Sections:

Name Size of data MD5
.text 757760 49ad5ade57900eb09c21568811b0a18d
.rdata 143360 32f0c1a23129a891d42ccf750d240956
.data 45056 9c3767704f68dcaed14ea3b6bdb63ba7
.idata 12288 00619d898f294b2a0f0e880a17e32f45
.rsrc 40960 939107627f1249785aecd8e823776208
.reloc 73728 bc7100a1c1758d0abe8c9df4b0a1451a
.text 188416 915dc176a9515a0d21b3828c837ffd1f
ogpnnef 0 00000000000000000000000000000000
.text 315392 c8004aeac00c8366d175633ed299c76c

More information:

Download GridinSoft Anti-Malware - Removal tool for SETUP32.EXE