How to remove ShellEh6055.dll
- File Details
- Overview
- Analysis
ShellEh6055.dll
The module ShellEh6055.dll has been detected as Ransom.Locky
File Details
Product Name: |
|
Company Name: |
|
MD5: |
0eb9f7fb524730f1b65cd926a55cbd70 |
Size: |
55 KB |
First Published: |
2018-10-12 10:04:17 (6 years ago) |
Latest Published: |
2020-08-17 18:31:53 (4 years ago) |
Status: |
Ransom.Locky (on last analysis) |
|
Analysis Date: |
2020-08-17 18:31:53 (4 years ago) |
%programfiles% |
%programfiles% |
%programfiles% |
%programfiles% |
%programfiles% |
%programfiles% |
%programfiles% |
%programfiles% |
%sysdrive%\system volume information\_restore{7d82b61b-3b2f-4e73-ba8b-9a80b2de28b0} |
%programfiles% |
|
23.1% |
|
|
23.1% |
|
|
23.1% |
|
|
7.7% |
|
|
7.7% |
|
|
7.7% |
|
|
7.7% |
|
Windows 10 |
46.2% |
|
Windows 7 |
38.5% |
|
Windows XP |
15.4% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x0000b320 |
Name |
Size of data |
MD5 |
CODE |
41984 |
8e9e9bd0841526ef95674bf0b8a381b8 |
DATA |
1536 |
8ce23468cfd3b95151dd7205b08b35ed |
BSS |
0 |
00000000000000000000000000000000 |
.idata |
3072 |
a1e9a00417a59f366fb7e53e02dea24b |
.edata |
512 |
81db179daa22f7e17e8ca0ff52cade43 |
.reloc |
4096 |
3cb3367b17aa549b5262ff45b17e3307 |
.rsrc |
4608 |
90f65c0f2832aa2e37ce9a81d6cc560b |