How to remove WeMod.exe
WeMod.exe
The module WeMod.exe has been detected as Trojan.Wacatac
File Details
| Product Name: | WeMod |
| Company Name: | WeMod |
| MD5: | 16bfa2cfe254d969c228b3fc13c9459e |
| Size: | 130 MB |
| First Published: | 2025-02-04 23:01:28 (9 months ago) |
| Latest Published: | 2025-02-04 23:01:28 (9 months ago) |
| Status: | Trojan.Wacatac (on last analysis) | |
| Analysis Date: | 2025-02-04 23:01:28 (9 months ago) |
Overview
| Signed By: | WeMod LLC |
| Status: | Valid |
Common Places:
| %localappdata%\squirreltemp\tempd\lib |
Geography:
| 100.0% |
OS Version:
| Windows 10 | 100.0% |
Analysis
| Subsystem: | Windows GUI |
| PE Type: | pe |
| OS Bitness: | 32 |
| Image Base: | 0x00400000 |
| Entry Address: | 0x037fa850 |
PE Sections:
| Name | Size of data | MD5 |
| .text | 110592512 | f412baa9f2fb31ed56748bb5604eb857 |
| .rdata | 21052416 | 3d957ad0362c651b5fe5c8475745ebec |
| .data | 487936 | 2edba07011d3c48783880fafbafb14a4 |
| .00cfg | 512 | b6b0bdabd6acf1a3c80d211e088b8fa2 |
| .rodata | 2560 | cce326712ebe143ce83eff8afbdba7b9 |
| .tls | 512 | c63553d40fa6ee68787f8dd857037999 |
| .voltbl | 512 | c622d8fb87d30a7fcab2c0d730647de6 |
| CPADinfo | 512 | 842689af09e7bf563672a4b43f1a2286 |
| malloc_h | 512 | 3573ccfe2dee8f0bcabad023a08e7572 |
| .rsrc | 348672 | b9b894f6484cfb24bba26fb9e5daa9cc |
| .reloc | 4012032 | 61d9b6aa302eb3cc8a53987f75d2bb83 |
More information:
Download GridinSoft
Anti-Malware - Removal tool for WeMod.exe