How to remove TrashReg.exe
- File Details
- Overview
- Analysis
TrashReg.exe
The module TrashReg.exe has been detected as Ransom.Wacatac
File Details
| Product Name: |
|
| Company Name: |
|
| MD5: |
4a342013856a515190f98fb4d25d9563 |
| Size: |
292 KB |
| First Published: |
2020-08-27 22:36:43 (5 years ago) |
| Latest Published: |
2024-04-13 23:02:12 (2 years ago) |
| Status: |
Ransom.Wacatac (on last analysis) |
|
| Analysis Date: |
2024-04-13 23:02:12 (2 years ago) |
| %sysdrive%\$recycle.bin\s-1-5-21-1017811095-421661674-995192615-1001\$rkgl8xs\total_commander_8.52_x86-x64_extremepack_2015.8_portable\soft\soft\-soft |
| %programfiles%\total\soft\-soft |
Analysis
| Subsystem: |
Windows GUI |
| PE Type: |
pe |
| OS Bitness: |
32 |
| Image Base: |
0x00400000 |
| Entry Address: |
0x000dcd5c |
| Name |
Size of data |
MD5 |
| .text |
0 |
d41d8cd98f00b204e9800998ecf8427e |
| .data |
0 |
d41d8cd98f00b204e9800998ecf8427e |
| .rsrc |
20480 |
01486fa8b4c65fa8fe19323d2ea15367 |
| .upx0 |
0 |
d41d8cd98f00b204e9800998ecf8427e |
| .upx1 |
274432 |
cba520d51bfc0818ef3ecb8939b0a7db |