How to remove SwapPatientName.exe
- File Details
- Overview
- Analysis
SwapPatientName.exe
The module SwapPatientName.exe has been detected as Worm.Ramnit
File Details
Product Name: |
|
Company Name: |
|
MD5: |
e5a428e07e26b2068c25d7dee3e17635 |
Size: |
131 KB |
First Published: |
2018-10-02 20:05:20 (6 years ago) |
Latest Published: |
2018-10-02 20:05:20 (6 years ago) |
Status: |
Worm.Ramnit (on last analysis) |
|
Analysis Date: |
2018-10-02 20:05:20 (6 years ago) |
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x00014000 |
Name |
Size of data |
MD5 |
.text |
12288 |
199b0343e4bcda72d3d8fd5ad0099feb |
.rdata |
9216 |
5a48f4dd754c20a9a63ac4d7b5ce40eb |
.data |
512 |
6a5b89b8aec3454969cdc5b376f39ccd |
.rsrc |
44032 |
575a82f18a7e162a9216d36dbd2b4a6b |
.reloc |
2560 |
2e426d86431f5311bc2fa5ee75de5dcd |
.text |
64512 |
91d5c9950953cc0f57871266cc6d6edf |